Getting Data In

Use tokens in a saved search dispatch via the Python SDK

cdhippen
Path Finder

Currently we have a list of searches that we run via the Python SDK by passing in a json file that has the queries, labels, and fields. Seeing as we can save searches and use inputs in the GUI, it stands to reason that we should be able to access these searches and replace tokens within the application rather than having to maintain a large json file. Is there any way to use searches with tokens via the python sdk, perhaps the dispatch() method?

0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...