export search results using curl


I was advised that curl was a workaround used for exporting search results to csv.
Problem is I do not know how to export specific jobs in the jobs manager and I need assistance with the correct syntax:

curl -k -u admin:password! -o 120979_curl.csv --data-urlencode search="search source=log.tar.*" -d "output_mode=csv" exampleurl:8089/servicesNS/admin/search/search/jobs/export

I suspect it is not working because of the search= source=log.tar.* being incorrect... What should I be adding in this field so I download the correct job?

The search I ran was the following
search * | regex _raw=".*/[a-f0-9]{32}/[a-z]{1,15}-[a-z]{1,15}.php" and this is how it appears in teh job manager.

Lastly if I wanted to view the search jobs results on the cli - where would I find the results and couldn't I just scp this file off instead of using curl?

Tags (2)
0 Karma


Saw this in another post that shows the correct format of the dataurl encode ( )

So the command should be something like :

curl -k -u admin:password -d "output_mode=csv" -o /home/sample1.csv
--data-urlencode 'search=search earliest=-1d@d latest=@d index=blah

0 Karma

New Member

I ran a search using this syntax, and received the error "curl: option --data-urlencode: is unknown"

Any ideas?

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...