Splunk Search

Create Search using REST/JSON

Tops_NI
Engager

I can successfully create a search job with the help of the docs using a Curl command:

curl -u "userName" -k https://host:port/services/search/jobs -d search="encodedSearchQuery"

I get back the SID as expected:

<response>
<sid>1234567890.123456</sid>
</response>

 

When I try to translate this search to a REST Call with JSON body I cannot get it to work. For example if I use postman:

POST

https://host:port/services/search/jobs/

Request Body (JSON)

{
"search": "encodedSearchQuery"
}

 

I get a 200 but no Search job created or SID returned.

 

Any tips to get this working?

Thanks

Labels (1)
0 Karma
1 Solution

Tops_NI
Engager

Seems I had to post the data as Key Value pairs using Content Type application/x-www-form-urlencoded rather than a JSON request body.

View solution in original post

0 Karma

Tops_NI
Engager

Seems I had to post the data as Key Value pairs using Content Type application/x-www-form-urlencoded rather than a JSON request body.

View solution in original post

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.