Tableau Connector for Splunk

Build 26.0.9770

ExecuteSearchJob

Runs a Splunk search job and returns its results in a single call. Internally the procedure creates the search job (an INSERT on SearchJobs), waits for it to finish, and then reads the results (ReadJobResults), removing the need to perform those steps separately. The input parameters mirror the insertable fields of the SearchJobs table.

Input

Name Type Required Description
EventSearch String True The search to run, supplied as Splunk Search Processing Language (SPL). The value is sent to Splunk exactly as provided; the REST API does not implicitly prepend the 'search' command, so the query must begin with the 'search' command (for example, 'search index=_internal | head 1') or with a leading pipe for a generating command (for example, '| tstats count by host').
EarliestTime String False The earliest time a search job is configured to start. Can be a UTC time, a relative time specifier (to now), or a formatted time string.
LatestTime String False The latest time a search job is configured to start. Can be a UTC time, a relative time specifier (to now), or a formatted time string.
Custom String False Custom job property. Pass the values as a comma-separated list of pairs of keys and values.
SearchMode String False Searching mode, normal or realtime. If set to realtime, the search runs over the live data.

The allowed values are normal, realtime.

EnableLookups Boolean False Indicates whether lookups should be applied to events.
AutoPause Integer False If specified, the search job pauses after this many seconds of inactivity. (0 means never autopause.)
AutoCancel Integer False If specified, the job automatically cancels after this many seconds of inactivity. (0 means never autocancel.)
ForceBundleReplication Boolean False Specifies whether this search should cause (and wait, depending on SyncBundleReplication) for bundle synchronization with all search peers.
IndexEarliest String False Sets the earliest inclusive time bounds for the search, based on the index time bounds.
IndexLatest String False Sets the latest exclusive time bounds for the search, based on the index time bounds.
IndexedRealtime Boolean False Indicates whether or not to use the indexed-realtime mode for real-time searches.
IndexedRealtimeOffset Integer False Sets the disk sync delay for indexed real-time search, in seconds.
MaxCount Integer False The number of events that can be accessible in any given status bucket.
MaxTime Integer False The number of seconds to run this search before finalizing. Specify 0 to never finalize.
Namespace String False The application namespace in which to restrict searches.
Now String False Sets the absolute time used for any relative time specifier in the search. Defaults to the current system time. A relative time modifier (for example, +2d) may be used.
ReduceFrequency Integer False Determines how frequently to run the MapReduce reduce phase on accumulated map values.
ReloadMacros Boolean False Specifies whether to reload macro definitions from the configuration file.
RemoteServerList String False A comma-separated list of (possibly wildcarded) servers from which raw events should be pulled.
ReplaySpeed Integer False Indicates a real-time search replay speed factor. For example, 1 is normal speed, 0.5 is half speed, and 2 is twice normal speed.
ReplayStartTime String False Relative wall-clock start time for the replay.
ReuseMaxSecondsAgo Integer False Specifies the number of seconds ago to check when an identical search is started, returning the search Id of that job instead of starting a new one.
RequiredField String False Adds a required field to the search.
RealTimeBlocking Boolean False For a real-time search, indicates if the indexer blocks if the queue for this search is full.
RealTimeIndexFilter Boolean False For a real-time search, indicates if the indexer prefilters events.
RealTimeMaxBlockSecs Integer False For a real-time search with RealTimeBlocking set to true, the maximum time to block. Specify 0 to indicate no limit.
RealTimeQueueSize Integer False For a real-time search, the queue size (in events) that the indexer should use for this search.
StatusBuckets Integer False The maximum number of status buckets to generate. 0 indicates not to generate timeline information.
Timeout Integer False The number of seconds to keep this search after processing has stopped.
SyncBundleReplication String False Specifies whether this search should wait for bundle replication to complete.
PollWaitingTime Integer False The number of seconds to wait between checks of the search job's status while waiting for it to complete. Defaults to 5.
PollingTimeout Integer False The maximum number of seconds to wait for the search job to complete before the procedure stops polling and returns an error. Set to 0 to wait indefinitely. Defaults to 60.
UserContext String False Set this value to read the results from the /servicesNS/{UserContext}/{AppContext} node. Required if AppContext is present. If left unspecified, the node /services is used.
AppContext String False Set this value to read the results from the /servicesNS/{UserContext}/{AppContext} node. Required if UserContext is present. If left unspecified, the node /services is used.

Result Set Columns

Name Type Description
* String The fields returned by the search. The columns vary depending on the search query.

Copyright (c) 2026 CData Software, Inc. - All rights reserved.
Build 26.0.9770