Security

REST API output - ID field doesn't have port information for standalone instance

rahulroy_splunk
Path Finder

I'm on Splunk 6.2.6. I have a SHC (3 nodes) and a deployment server (standalone box). So when I run a search with rest command, the id field format is different in my SHC nodes and deployment server nodes.

For example, if I run this

| rest /servicesNS/-/-/saved/searches splunk_server=local | head 1 | table id

The output on SHC nodes would be

id
http://<SHCNodeName>:<mgtmt_port>/servicesNS/nobody/search/saved/searches/somesname

Whereas, the same would return this on my standalone Deployment server.

id
http://127.0.0.1/servicesNS/nobody/search/saved/searches/somesname

I believe 127.0.0.1 is localhost but no port information , hence making the id field value unreachable (planning to some automation using this id/url).

Any idea why it doesn't show a valid url in the id field on standalone instance? I don't see any explicit config on SHC node where it works.

0 Karma

renjith_nair
Legend

Hi @rahulroy_splunk,

Check mgmtHostPort configuration of your standalone instance in web.conf. https://docs.splunk.com/Documentation/Splunk/7.1.1/Admin/Webconf

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...