Splunk Enterprise

Download raw Splunk logs via api

vj_hawk21
Explorer

Team,

how to remotely execute a search and download the search results and store in a shared drive or a CSV file.

Labels (2)
0 Karma

vj_hawk21
Explorer

Hi @rnowitzki 

Thanks for your response.

I have created the search but not able to find its sid/vsid/searc_id.. how to identify the SID?

Thx 

VJ

0 Karma

rnowitzki
Builder

Hi @vj_hawk21 ,

When you created the Job, the sid was in the response.

 <sid>1258421375.19</sid>


Also, you can get a list of your searches with

curl -u admin:changeme -k https://localhost:8089/services/search/jobs/

 

BR
Ralph

--
Karma and/or Solution tagging appreciated.
0 Karma

rnowitzki
Builder

Hi @vj_hawk21,

Please check the documentation about the REST API:

https://docs.splunk.com/Documentation/Splunk/8.0.6/RESTTUT/RESTsearches

You create a search job, get the sid back and with the sid you can get the results.

To receive the results as csv, you would have to use output_mode=csv  as indicated here

BR
Ralph

--
Karma and/or Solution tagging appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...