Splunk Search

How to query a lookup table using the REST API?

raduand
Explorer

Hi guys,

I have a Splunk scheduled search which is producing a list of URLs that need to be used by another system. The other system has to access the list using http/https protocol.

Now, what i'm looking for is:

Can someone guide me in how to achieve this?

Thanks in advance!
Andrei

Labels (1)
1 Solution

niketn
Legend

@raduand, Splunk search results can be pushed to lookup file using outputlookup. (Refer to documentation: http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Outputlookup)

Within Splunk you can read csv file using inpulookup command. ( Refer to documentation: http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/inputlookup)

You can create report with inputlookup command to list the contents of the csv file and the pull the Report results using REST API search/jobs/{search_id}/results. Refer to documentation: http://docs.splunk.com/Documentation/Splunk/latest/RESTREF/RESTsearch#search.2Fjobs.2F.7Bsearch_id.7...

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

jkat54
SplunkTrust
SplunkTrust
 search="| inputlookup lookupname.csv"
0 Karma

niketn
Legend

@raduand, Splunk search results can be pushed to lookup file using outputlookup. (Refer to documentation: http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Outputlookup)

Within Splunk you can read csv file using inpulookup command. ( Refer to documentation: http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/inputlookup)

You can create report with inputlookup command to list the contents of the csv file and the pull the Report results using REST API search/jobs/{search_id}/results. Refer to documentation: http://docs.splunk.com/Documentation/Splunk/latest/RESTREF/RESTsearch#search.2Fjobs.2F.7Bsearch_id.7...

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

hettervik
SplunkTrust
SplunkTrust

This is great, but is there any way of finding the "search_id" of a scheduled search? I've tried using the search_id that is listed in the URL when opening the search in the GUI and the search_is that is listed on the enpoint https://<host>:<mPort>/services/search/jobs (which I found to be not the same for some reason), but I always get the result "Unknown endpoint".

Anyone know how to find the correct ID for a scheduled search?

0 Karma

rhirasin
Engager

Thanks  lot @niketn ,

you solution work perfectly,

we really miss you... 😞 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...