Is it possible to run a saved search on a remote splunk server using the rest search command?


I'm wondering if there is an equivalent way to do this with the rest search command:

curl -k -u admin:changeme -d "search=savedsearch CIF%3Adomain_botnet" -d "outputmode=csv" https://localhost:8089/servicesNS/admin/search/search/jobs/export -o domainbotnet.csv

That runs the saved search called CIF:domain_botnet.

Is that possible?



Tags (3)
0 Karma


Hi responsys_cm,

sure, have you seen the saved search REST API docs?

There are also some examples in the SDKs available:
For Java -

For C# -

hope this helps ...

cheers, MuS


I looked through the API doc, though I'm not a developer...

It would seem that something like this should work:

| rest /servicesNS/craig/saved/searches/InputDomain/dispatch splunk_server= get-arg-name="" get-arg-value="true"

But that never gets any results. Nor does it produce any kind of error.

I'm also unclear on how to authenticate to the remote Splunk server using the rest command...