ExecuteSearchJob
Runs a Splunk search job and returns its results in a single call. Internally the procedure creates the search job (an INSERT on SearchJobs), waits for it to finish, and then reads the results (ReadJobResults), removing the need to perform those steps separately. The input parameters mirror the insertable fields of the SearchJobs table.
Input
| Name | Type | Required | Description |
| EventSearch | String | True | The search to run, supplied as Splunk Search Processing Language (SPL). The value is sent to Splunk exactly as provided; the REST API does not implicitly prepend the 'search' command, so the query must begin with the 'search' command (for example, 'search index=_internal | head 1') or with a leading pipe for a generating command (for example, '| tstats count by host'). |
| EarliestTime | String | False | The earliest time a search job is configured to start. Can be a UTC time, a relative time specifier (to now), or a formatted time string. |
| LatestTime | String | False | The latest time a search job is configured to start. Can be a UTC time, a relative time specifier (to now), or a formatted time string. |
| Custom | String | False | Custom job property. Pass the values as a comma-separated list of pairs of keys and values. |
| SearchMode | String | False | Searching mode, normal or realtime. If set to realtime, the search runs over the live data.
The allowed values are normal, realtime. |
| EnableLookups | Boolean | False | Indicates whether lookups should be applied to events. |
| AutoPause | Integer | False | If specified, the search job pauses after this many seconds of inactivity. (0 means never autopause.) |
| AutoCancel | Integer | False | If specified, the job automatically cancels after this many seconds of inactivity. (0 means never autocancel.) |
| ForceBundleReplication | Boolean | False | Specifies whether this search should cause (and wait, depending on SyncBundleReplication) for bundle synchronization with all search peers. |
| IndexEarliest | String | False | Sets the earliest inclusive time bounds for the search, based on the index time bounds. |
| IndexLatest | String | False | Sets the latest exclusive time bounds for the search, based on the index time bounds. |
| IndexedRealtime | Boolean | False | Indicates whether or not to use the indexed-realtime mode for real-time searches. |
| IndexedRealtimeOffset | Integer | False | Sets the disk sync delay for indexed real-time search, in seconds. |
| MaxCount | Integer | False | The number of events that can be accessible in any given status bucket. |
| MaxTime | Integer | False | The number of seconds to run this search before finalizing. Specify 0 to never finalize. |
| Namespace | String | False | The application namespace in which to restrict searches. |
| Now | String | False | Sets the absolute time used for any relative time specifier in the search. Defaults to the current system time. A relative time modifier (for example, +2d) may be used. |
| ReduceFrequency | Integer | False | Determines how frequently to run the MapReduce reduce phase on accumulated map values. |
| ReloadMacros | Boolean | False | Specifies whether to reload macro definitions from the configuration file. |
| RemoteServerList | String | False | A comma-separated list of (possibly wildcarded) servers from which raw events should be pulled. |
| ReplaySpeed | Integer | False | Indicates a real-time search replay speed factor. For example, 1 is normal speed, 0.5 is half speed, and 2 is twice normal speed. |
| ReplayStartTime | String | False | Relative wall-clock start time for the replay. |
| ReuseMaxSecondsAgo | Integer | False | Specifies the number of seconds ago to check when an identical search is started, returning the search Id of that job instead of starting a new one. |
| RequiredField | String | False | Adds a required field to the search. |
| RealTimeBlocking | Boolean | False | For a real-time search, indicates if the indexer blocks if the queue for this search is full. |
| RealTimeIndexFilter | Boolean | False | For a real-time search, indicates if the indexer prefilters events. |
| RealTimeMaxBlockSecs | Integer | False | For a real-time search with RealTimeBlocking set to true, the maximum time to block. Specify 0 to indicate no limit. |
| RealTimeQueueSize | Integer | False | For a real-time search, the queue size (in events) that the indexer should use for this search. |
| StatusBuckets | Integer | False | The maximum number of status buckets to generate. 0 indicates not to generate timeline information. |
| Timeout | Integer | False | The number of seconds to keep this search after processing has stopped. |
| SyncBundleReplication | String | False | Specifies whether this search should wait for bundle replication to complete. |
| PollWaitingTime | Integer | False | The number of seconds to wait between checks of the search job's status while waiting for it to complete. Defaults to 5. |
| PollingTimeout | Integer | False | The maximum number of seconds to wait for the search job to complete before the procedure stops polling and returns an error. Set to 0 to wait indefinitely. Defaults to 60. |
| UserContext | String | False | Set this value to read the results from the /servicesNS/{UserContext}/{AppContext} node. Required if AppContext is present. If left unspecified, the node /services is used. |
| AppContext | String | False | Set this value to read the results from the /servicesNS/{UserContext}/{AppContext} node. Required if UserContext is present. If left unspecified, the node /services is used. |
Result Set Columns
| Name | Type | Description |
| * | String | The fields returned by the search. The columns vary depending on the search query. |