Splunk Search

How to search with the metadata command using the Python API?

lohitkidu
Path Finder

Hi ,

I am not sure how to use the metadata command using the Python API as it is required to be the first command like | metadata type=hosts, but when we use the Python API every search has to be appended by search like search index=abc.

In case of metadata, if I use search metadata type=hosts or search | metadata type=hosts, none of them are working.

Any ideas how to use it?

0 Karma
1 Solution

lohitkidu
Path Finder

It turns out that while using metadata command over API, we do not require search command as a prefix.

View solution in original post

0 Karma

lohitkidu
Path Finder

It turns out that while using metadata command over API, we do not require search command as a prefix.

0 Karma

somesoni2
Revered Legend

Try this as the search query

search index=_internal | head 1 | map maxsearches=1 "| metadata type=hosts"
0 Karma

lohitkidu
Path Finder

Never worked for me.

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...