Skip to main content

Run Saved Search

Runs a saved search in Splunk.

This node is also exposed as an AI Agent tool.

This node has 1 input port and 1 output port.

Common Properties

Every node shares these.

  • Name — the node's display name on the canvas.
  • Color — the node's colour on the canvas.
  • Delay Before (sec) — wait this long before the node runs.
  • Delay After (sec) — wait this long after the node runs.
  • Continue On Error — carry on instead of failing the flow. Defaults to false.
info

When Continue On Error is true the error is not raised at all, so a Catch node will not see it either.

Inputs

PropertyFieldDescription
Client IDinClientIDClient ID from Connect node
Saved Search NameinSearchNameName of the saved search to dispatch

Outputs

PropertyFieldDescription
Result CountoutCountNumber of results returned
ResultsoutResultsSearch results as array of objects
Search IDoutSIDDispatched search job ID (SID)

Options

PropertyFieldDescription
Base URLoptBaseURLSplunk management API URL
CredentialsoptCredentialsSplunk Auth Token credentials
Max ResultsoptMaxResultsMaximum number of results to return
Skip TLS VerificationoptSkipTLSSkip TLS certificate verification
Timeout (seconds)optTimeoutMaximum time in seconds to wait for search to complete

Requirements

  • A Client ID from this package's Connect node, unless you set credentials directly on this node.
  • Splunk Auth Token — Splunk authentication token for REST API access
    • value — Auth Token (password, required). Splunk authentication token from Settings > Tokens

Store these in a Vault and reference the vault item from the node, rather than typing the secret into the property.

Run Search · Get Search Results · List Saved Searches

Elsewhere in the package: Connect · Disconnect · Send Event · List Indexes · Get Server Info · Toolkit

See also