Splunk Search

My curl searches result in "Unparsable URI-encoded request data". Is curl version 7.15.5 unsupported?

benjaminw
New Member

My curl searches result in the output

Unparsable URI-encoded request data

I see that many of the curl searches on this site include the switch --data-urlencode, but when I include this in my searches, curl replies that the feature is unknown. My curl version is 7.15.5, and the latest version available is 7.49ish. Can anyone confirm that the --data-urlencode feature is necessary to perform some searches, or that my version of curl is outdated for Splunk queries?

Many thanks!

Tags (4)
0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

You will not require --data-urlencode if you want to encode your own url manually

for example... equals sign (=) becomes %3d once encoded.

You can use an online encoder like this one instead of --data-urlencode
http://meyerweb.com/eric/tools/dencoder/

When i encode the url of my answer i get:
https%3A%2F%2Fanswers.splunk.com%2Fanswers%2F418333%2Fmy-curl-searches-result-in-unparsable-uri-encoded.html%23answer-418465

So now I could use:

curl -k 'https%3A%2F%2Fanswers.splunk.com%2Fanswers%2F418333%2Fmy-curl-searches-result-in-unparsable-uri-encoded.html%23answer-418465'

View solution in original post

jkat54
SplunkTrust
SplunkTrust

You will not require --data-urlencode if you want to encode your own url manually

for example... equals sign (=) becomes %3d once encoded.

You can use an online encoder like this one instead of --data-urlencode
http://meyerweb.com/eric/tools/dencoder/

When i encode the url of my answer i get:
https%3A%2F%2Fanswers.splunk.com%2Fanswers%2F418333%2Fmy-curl-searches-result-in-unparsable-uri-encoded.html%23answer-418465

So now I could use:

curl -k 'https%3A%2F%2Fanswers.splunk.com%2Fanswers%2F418333%2Fmy-curl-searches-result-in-unparsable-uri-encoded.html%23answer-418465'

benjaminw
New Member

Jkat54, thank you! This encoding site is exactly what I needed!

0 Karma

jkat54
SplunkTrust
SplunkTrust

You are very welcome @benjaminw

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...