Splunk Search

How can i retrieve the SID of a saved search by curl?

Robertoing
Explorer

How can i retrieve the SID of a saved search by curl?

Labels (1)
0 Karma

manjunathmeti
Champion

Then you can call your saved search using /search/jobs:

curl -u admin:changeme -k https://localhost:8089/services/search/jobs -d search="| savedsearch saved_search_name"

 You'll get SID in the response:

<response><sid>mysearch_02151949</sid></response>

And use /search/jobs/SID/results to get results:

curl -k -u admin:pass https://localhost:8089/services/search/jobs/mysearch_02151949/results

 

If this reply helps you, an upvote/like would be appreciated.

0 Karma

manjunathmeti
Champion

hi @Robertoing ,

You can use below API endpoint.

https://<host>:<mPort>/services/saved/searches/{name}/history

 

Check this for more info: https://docs.splunk.com/Documentation/SplunkCloud/8.1.2012/RESTREF/RESTsearch#saved.2Fsearches.2F.7B...

 

If this reply helps you, an upvote/like would be appreciated.

 

0 Karma

Robertoing
Explorer

If the saved search is scheduled, but my saved search no. How can i start my saved search and get the SID to see the results?

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...