Reporting

Is it possible to run a saved search on a remote splunk server using the rest search command?

responsys_cm
Builder

I'm wondering if there is an equivalent way to do this with the rest search command:

curl -k -u admin:changeme -d "search=savedsearch CIF%3Adomain_botnet" -d "output_mode=csv" https://localhost:8089/servicesNS/admin/search/search/jobs/export -o domain_botnet.csv

That runs the saved search called CIF:domain_botnet.

Is that possible?

Thx.

Craig

Tags (3)
0 Karma

MuS
Legend

Hi responsys_cm,

sure, have you seen the saved search REST API docs?

There are also some examples in the SDKs available:
For Java - http://dev.splunk.com/view/java-sdk/SP-CAAAEKY#runsavedargs

For C# - http://dev.splunk.com/view/csharp-sdk/SP-CAAAEQF#runsavedargs

hope this helps ...

cheers, MuS

responsys_cm
Builder

I looked through the API doc, though I'm not a developer...

It would seem that something like this should work:

| rest /servicesNS/craig/saved/searches/InputDomain/dispatch splunk_server=10.10.10.10 get-arg-name="dispatch.now" get-arg-value="true"

But that never gets any results. Nor does it produce any kind of error.

I'm also unclear on how to authenticate to the remote Splunk server using the rest command...

Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...