Is it possible to run a saved search on a remote splunk server using the rest search command?


I'm wondering if there is an equivalent way to do this with the rest search command:

curl -k -u admin:changeme -d "search=savedsearch CIF%3Adomain_botnet" -d "output_mode=csv" https://localhost:8089/servicesNS/admin/search/search/jobs/export -o domain_botnet.csv

That runs the saved search called CIF:domain_botnet.

Is that possible?



Tags (3)
0 Karma


Hi responsys_cm,

sure, have you seen the saved search REST API docs?

There are also some examples in the SDKs available:
For Java -

For C# -

hope this helps ...

cheers, MuS


I looked through the API doc, though I'm not a developer...

It would seem that something like this should work:

| rest /servicesNS/craig/saved/searches/InputDomain/dispatch splunk_server= get-arg-name="" get-arg-value="true"

But that never gets any results. Nor does it produce any kind of error.

I'm also unclear on how to authenticate to the remote Splunk server using the rest command...

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...