Splunk Search

Splunk returns zero results using REST API

kvmadan
Explorer

I'm trying to search a query and retrieve the results through REST API, and it returns zero results. Below queries, i am using to submit the search, check the status of the dispatch, and retrieve the results.

https://splunk.corp.net:8089/servicesNS/admin/search/search/jobs

https://splunk.corp.net:8089/services/search/jobs/{{sid}}?output_mode=json

https://splunk.corp.net:8089/services/search/jobs/{{sid}}/results

The same query executed from the Splunk UI, returns the results. Also, the UI returns results in a fraction of second, but in case of REST API, it takes more than ~5 minutes to complete the search (dispatchState = DONE) and returns zero results.

Its is the same case for any search i do with REST API.

Any idea, what am I doing wrong here?

Tags (4)
0 Karma

manjunathmeti
Champion

Can you post code snippet doing post call to /search/jobs?

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...