Getting Data In

Is there a way to return a search.log for a recent search job using the REST api?

bschaap
Path Finder

I'd like to monitor for certain text in a search.log for recent jobs.

Is there a way to return a search.log for a recent search job using the REST api?

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi @bschaap,

If you know the Job ID then you can use below REST API

curl -k -u admin:pass https://<server>:<mgmt_port>/services/search/jobs/<job_id>/search.log

View solution in original post

harsmarvania57
Ultra Champion

Hi @bschaap,

If you know the Job ID then you can use below REST API

curl -k -u admin:pass https://<server>:<mgmt_port>/services/search/jobs/<job_id>/search.log

bschaap
Path Finder

Thank you that works

0 Karma

harsmarvania57
Ultra Champion

Great. I have converted my comment to answer so you can accept/upvote it.

0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...