Splunk Cloud Platform

can you create searches using the REST API in splunk cloud

adeyoyeniyi
New Member

can you create searches using the REST API in splunk cloud

Labels (1)
0 Karma

akapa
Engager

Yes, you can create searches using the REST API in Splunk Cloud. Here are the basic steps:

  1. Get a Session Key: Authenticate with Splunk to get a session key.
  2. Create a Search Job: Use the /services/search/jobs endpoint to create a search job. You’ll need to send a POST request with your search query in the body.
  3. Check Search Status: Use the search ID (sid) returned from the previous step to check the status of your search job.

Here’s a simple example using curl:

curl -k -u username:password https://<splunk-cloud-url>/services/search/jobs -d search="search index=_internal | head 10"

This command will create a search job that retrieves the first 10 events from the _internal index.

 
 
0 Karma

KendallW
Contributor
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...