Getting Data In

Rest api add parameters to a saved search

Oti47
Path Finder

Hi,

I’m using the rest api with curl now I got the following question:

Is it possible to add parameters to a saved search so I can specify my search by the IP 192.168.178.1 and I get results only with this IP something like:

curl --get -k -u admin:changeme -d "output_mode=csv" -d "count=5"  'search="search IP=192.168.178.1 https://localhost:8089/servicesNS/admin/search/search/jobs/1350986028.108/results

Thanks in Advance

Tags (1)

brettcave
Builder

Yes, you can. You can schedule the search job, and supply a post filter when retrieving results. See http://docs.splunk.com/Documentation/Splunk/5.0.2/RESTAPI/RESTsearch#search.2Fjobs.2F.7Bsearch_id.7D...

You should be able to use the exact parameters you used in your example. However, your search string needs to be URL-encoded:

... -d "count=5" -d "search=IP%3D192.168.178.1" https://localhost:8089/../.
0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...