Splunk Search

Are there any policy on Splunk would block REST API searches?

sunilr8
New Member

i am trying to search over REST API, seeing "All Time searches don't adhere to Splunk best practices" Error.  Any policy on Splunk would block REST API searches ?

curl -u 'XXXX' -k https://splunkapi.example.com/services/search/jobs -d search='search index="webaccess" status=403 earliest_time=-1d'

curl -u 'XXXX' -k https://splunkapi.example.com/services/search/jobs -d search='search index="webaccess" status=403 earliest=-1d@d latest=now()'

 

<?xml version="1.0" encoding="UTF-8"?>
<response>
<messages>
<msg type="FATAL">Please reduce your search to a smaller time range. All Time searches don't adhere to Splunk best practices</msg>
</messages>
</response>

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Try specifying timerange as parameters to the rest call, not as parameters within the search.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...