I am querying Splunk using javascript SDK. In the searchParams, i have given the output mode as "json_rows".
var searchParams = {
exec_mode: "normal",
output_mode: "json_rows"
};
Any idea what is going wrong? I tried "json_cols" and only "json" also. Same result.
Thanks in advance.
The docs are not very clear on this so I'm not really sure, but have you tried capitals?
"output_mode: Specifies the output format of the results (XML, JSON, JSON_COLS, JSON_ROWS, CSV, ATOM, or RAW)."
http://dev.splunk.com/view/javascript-sdk/SP-CAAAEFA#oneshotjob