Building for the Splunk Platform

REST API Python example

Path Finder

I am testing out this script and it works with a few modifications on the endpoints I changed.


I changed the endpoint to:

/services/search/jobs/%s/results' % (sid),'GET'

My results are great, but they appear in xml format. Would I have to add "output_mode=csv" in the body argument?

body=urllib.urlencode({'search': searchQuery}))[1]
0 Karma
1 Solution

Ultra Champion

Ultra Champion

There is an example here :

Have you considered using the Splunk Python SDK , it makes what you are trying to do a lot simpler.

Some examples :

Path Finder

print httplib2.Http(disable_ssl_certificate_validation=True).request(base url +
+ '/services/search/jobs/%s/results' % (sid),'GET', headers={'Authorization': 'Splunk %s'
% sessionKey}, body=urllib.urlencode({'search': searchQuery}))[1]

The above will print out what this curl command would print out.

curl --get -k -u admin:splunker -d "count=100" https://localhost:8089/servicesNS/admin/search/search/jobs/1399938078.2/results

Where would I add content such as "output_mode=csv", that way the results being printed are user-friendly and easily readable?

0 Karma
Get Updates on the Splunk Community!

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...

Security Highlights | January 2023 Newsletter

January 2023 Splunk Security Essentials (SSE) 3.7.0 ReleaseThe free Splunk Security Essentials (SSE) 3.7.0 app ...

Platform Highlights | January 2023 Newsletter

 January 2023Peace on Earth and Peace of Mind With Business ResilienceAll organizations can start the new year ...