Hi could you please give me an advice how to edit a call to the Splunk Rest API with the following parameter:
search | inputlookup mylookup.csv
The goal is to use another APP, not the user default one.
I tried the following but it gave me same result:
| inputlookup mylookup.csv
| eval app_name = $env:MyNewApp$
Thanks a lot!
Hello
I was able to change the relative URL and successfully get the new app data -changing the default application search.
I used this article:
https://community.splunk.com/t5/Getting-Data-In/REST-API-with-namespace/m-p/9596
My API call looks like
https://splunkserver:8089/servicesNS/YOUR_USERNAME/TARGET_NAMESPACE/search/jobs
The TargetNamespace is the new APP (search header).
Thanks
You may find some helpful information at https://docs.splunk.com/Documentation/Splunk/8.2.3/RESTUM/RESTusing#Namespace
Thanks,
I am still not able to make this work
It would help if you shared the call you're trying.
Hello
I was able to change the relative URL and successfully get the new app data -changing the default application search.
I used this article:
https://community.splunk.com/t5/Getting-Data-In/REST-API-with-namespace/m-p/9596
My API call looks like
https://splunkserver:8089/servicesNS/YOUR_USERNAME/TARGET_NAMESPACE/search/jobs
The TargetNamespace is the new APP (search header).
Thanks