I can GET the definition of a saved search (report) from our dev server with a call like
curl -k -u me:word https://splunk-for-dev:8089/serviceNS/me/my-app/saved/searches/my-report
How do I use the resulting XML/JSON to POST to our prod server? The closest that I've found is something like
curl -k -u me:word https://splunk-for-prod:8089/serviceNS/me/my-app/saved/searches \
-d name=my-report -d search=...
But that means going through the XML/JSON and working out which are the non-default values and a whole lot of text munging. Surely there is a way that I can just post the XML/JSON that I've already got?
... View more