Splunk Search

Splunk search REST API - Is there a way to search searches containing white space without error?

splunkmagu
Explorer

Hi,

I'm using splunk web to check some searches/alerts:

1. | rest /servicesNS/-/-/saved/searches/ splunk_server=local | table title <-- displays a list of saved searches

then I pick one from the list and launch:

2. rest /servicesNS/-/-/saved/searches/alert_without_white_spaces splunk_server=local. <-- and it works

But when querying for a differently named alert I get an error:

3. rest /servicesNS/-/-/saved/searches/alert with white spaces splunk_server=local. <-- does not work
- error message: Error in 'rest' command: Invalid argument: '-'

3a) rest /servicesNS/-/-/saved/searches/'alert with white spaces' splunk_server=local.   <-- does not work
- error message: Error in 'rest' command: Invalid argument: '-'

3b) rest /servicesNS/-/-/saved/searches/"alert with white spaces" splunk_server=local.   <-- does not work
- error message:

3d) rest /servicesNS/-/-/saved/searches/alert\ with\ white\ spaces splunk_server=local. 
- error message: Error in 'rest' command: Invalid argument: '-\'

3e) | eval alert1="alert with white spaces" 
        | rest /servicesNS/-/-/saved/searches/alert1
- error message (splunk didn't use the variable value but the variable name)


Is there a way to use variables or to query for a search name containing white spaces without getting an error ?

Labels (1)
0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

Most probably, it needs to be urlencoded.

You can do it "by hand" or use https://splunkbase.splunk.com/app/4146

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

Most probably, it needs to be urlencoded.

You can do it "by hand" or use https://splunkbase.splunk.com/app/4146

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...