Yes, you can create searches using the REST API in Splunk Cloud. Here are the basic steps: Get a Session Key: Authenticate with Splunk to get a session key. Create a Search Job: Use the /services/search/jobs endpoint to create a search job. You’ll need to send a POST request with your search query in the body. Check Search Status: Use the search ID (sid) returned from the previous step to check the status of your search job. Here’s a simple example using curl: curl -k -u username:password https://<splunk-cloud-url>/services/search/jobs -d search="search index=_internal | head 10"
This command will create a search job that retrieves the first 10 events from the _internal index.
... View more