Splunk Dev

Could anyone spot why the code is failing to create a search with HTTP POST?

ChintanaM
Explorer

Dear all,

I am trying to initiate a search using Splunk cloud rest API. Using following code

 

 

 

 

const accessToken = "--my-super-secret-token--";
const url = "https://company-installation.splunkcloud.com:8089/services/search/jobs";

try {
  const authHeaderValue = `Splunk ${accessToken}`;

  const config = {
    headers: {
      'Authorization': authHeaderValue
    },
    params: {
      'output_mode': 'json',
      'search':'search *'
    }
  };

  const res = await axios.post(url, config);

  return {
    statusCode: 200,
    body: JSON.stringify(res.data),
  };
  
} catch (e) {


  return {
    statusCode: 400,
    body: JSON.stringify(e),
  };
}

 

 

 

 

 

When the code is executed I get a 401 at line const res = await axios.post(url, config);

My api token is valid and my IP address is whitelisted

When axios.post is replaced with axios.get, I get list of searches back which also verifies token and IP address are good

Could anyone spot why the code is failing to create a search with HTTP POST please?

I am very new to Splunk REST API and any help is much appreciated

 

 

 

Labels (1)
0 Karma
1 Solution

ChintanaM
Explorer

Hi all,

The issue was on how axios was dealing with its payload. Just needed to encode data for to be able to calculate content-length.

Cheers

CM

View solution in original post

0 Karma

arsen_ye
New Member

Hi @ChintanaM

I'm also new to splunk and I faced to a problem, maybe you can help me. Does you search param works fine? I'm also trying to search with axios post request but I'm getting 26mb of data. It seems that my search parameter doesn't work and my request return all the data that exists.   

Thanks in advance.

0 Karma

ChintanaM
Explorer

Hi all,

The issue was on how axios was dealing with its payload. Just needed to encode data for to be able to calculate content-length.

Cheers

CM

0 Karma

Pat
Path Finder

Could you expand on this with what you had changed?  I have no idea what you meant by encode data.

0 Karma
Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...