Splunk Enterprise

Download raw Splunk logs via api

vj_hawk21
Explorer

Team,

how to remotely execute a search and download the search results and store in a shared drive or a CSV file.

Labels (2)
0 Karma

vj_hawk21
Explorer

Hi @rnowitzki 

Thanks for your response.

I have created the search but not able to find its sid/vsid/searc_id.. how to identify the SID?

Thx 

VJ

0 Karma

rnowitzki
Builder

Hi @vj_hawk21 ,

When you created the Job, the sid was in the response.

 <sid>1258421375.19</sid>


Also, you can get a list of your searches with

curl -u admin:changeme -k https://localhost:8089/services/search/jobs/

 

BR
Ralph

--
Karma and/or Solution tagging appreciated.
0 Karma

rnowitzki
Builder

Hi @vj_hawk21,

Please check the documentation about the REST API:

https://docs.splunk.com/Documentation/Splunk/8.0.6/RESTTUT/RESTsearches

You create a search job, get the sid back and with the sid you can get the results.

To receive the results as csv, you would have to use output_mode=csv  as indicated here

BR
Ralph

--
Karma and/or Solution tagging appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...