Getting Data In

Splunk using rest api to fetch app name / id

Dawson014
Path Finder

Hello fellow Splunkers,

I am using the following query to fetch the splunk app name in standalone search head -

| rest /services/search/jobs splunk_server=local 
| addinfo 
| where sid = info_sid 
| rename eai:acl.app as app_name
| fields + app_name

However, this same query is not working in SHC. It shows No results found
Any suggestions would be appreciated.

Thanks!

1 Solution

sdawsonkg
Path Finder

If you're running the query on a dashboard then this should work -

<your_base_query>
| eval app_name = $env:app$
| ...

However, this will not work if you are running the query on a search panel.

View solution in original post

sdawsonkg
Path Finder

If you're running the query on a dashboard then this should work -

<your_base_query>
| eval app_name = $env:app$
| ...

However, this will not work if you are running the query on a search panel.

Dawson014
Path Finder

This will do. Thanks!

sdawsonkg
Path Finder

Good. Cheers!

renjith_nair
Legend

Hi @Dawson014,
Try running just | rest /services/search/jobs and see if it works

---
What goes around comes around. If it helps, hit it with Karma 🙂

Dawson014
Path Finder

Tried this, worked once. Then again the same No Results founds

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...