ExecuteSearchQuery
Performs a search and streams the results back, identical to a POST on the search/jobs/export endpoint.
Input
| Name | Type | Required | Description |
| Search | String | True | The search query to run. Identical to the search parameter of POST search/jobs. |
| EarliestTime | String | False | Sets the earliest (inclusive) time bound for the search. The value can be a UTC time, a relative time specifier (to now), or a formatted time string. Refer to the Splunk Time modifiers documentation for accepted formats. |
| LatestTime | String | False | Sets the latest (exclusive) time bound for the search. The value can be a UTC time, a relative time specifier (to now), or a formatted time string. Refer to the Splunk Time modifiers documentation for accepted formats. |
Result Set Columns
| Name | Type | Description |
| * | String | The fields returned by the search. The columns vary depending on the search query. |