Splunk Search
Highlighted

Get action.script using REST/SDK

Explorer

Hello

Is there any way to get action.script/action.script.filename from searches/jobs using REST/SDK?
I am aware, we can get from savedsearches.

Tags (3)
0 Karma
Highlighted

Re: Get action.script using REST/SDK

SplunkTrust
SplunkTrust

No, the search/jobs endpoint doesn't provide that info. You'd have to take the report's ID built from the label, user, and app returned by search/jobs and look at the saved/searches endpoint as you found out already 🙂

Take a look at this example to illustrate:

| rest /services/search/jobs search="isSavedSearch=1" | rename eai:acl.app as app | fields author app label sid | map search="rest /servicesNS/$author$/$app$/saved/searches/$label$ | fields title action.script action.script.filename | eval sid=\"$sid$\""
0 Karma
Highlighted

Re: Get action.script using REST/SDK

Explorer

Thanks for the immediate reply. I understood the logic.
But I got the following error:
"The search result count (354) exceeds maximum (10), using max. To override it, set maxsearches appropriately."

I'm new to splunk search. Any help would be great.
Thank you again!!

0 Karma
Highlighted

Re: Get action.script using REST/SDK

SplunkTrust
SplunkTrust

By default the map command will only execute ten searches, see http://docs.splunk.com/Documentation/Splunk/6.1.1/SearchReference/map for reference. Add maxsearches=0 to disable the maximum entirely.

Consider filtering before the map, for example by app or search name - unless you want to see all 354 entries.

Highlighted

Re: Get action.script using REST/SDK

Explorer

yes, I did that. But it is returning "None"/No Results found.

0 Karma
Highlighted

Re: Get action.script using REST/SDK

SplunkTrust
SplunkTrust

Heh, it appears map may not like maxsearches=0 for an infinite number of searches, try setting it to 1000 instead.

Highlighted

Re: Get action.script using REST/SDK

Explorer

I did for 500. But no result.

0 Karma
Highlighted

Re: Get action.script using REST/SDK

SplunkTrust
SplunkTrust

Does running a single REST call for a saved search work based on values taken from the jobs call manually?

0 Karma
Highlighted

Re: Get action.script using REST/SDK

Explorer

Yes! I tried. But I didn't get any output.
|rest/servicesNS/* /* /saved/searches/* | fields title action.script action.script.filename |

0 Karma
Highlighted

Re: Get action.script using REST/SDK

SplunkTrust
SplunkTrust

I don't think wildcards work there.

0 Karma