Skip to main content

Run Search

Runs a search in Splunk.

This node is also exposed as an AI Agent tool.

This node has 1 input port and 1 output port.

Common Properties

Every node shares these.

  • Name — the node's display name on the canvas.
  • Color — the node's colour on the canvas.
  • Delay Before (sec) — wait this long before the node runs.
  • Delay After (sec) — wait this long after the node runs.
  • Continue On Error — carry on instead of failing the flow. Defaults to false.
info

When Continue On Error is true the error is not raised at all, so a Catch node will not see it either.

Inputs

PropertyFieldDescription
Client IDinClientIDClient ID from Connect node
Search QueryinQuerySPL search query (e.g. search index

Outputs

PropertyFieldDescription
Result CountoutCountNumber of results returned
ResultsoutResultsSearch results as array of objects
Search IDoutSIDSearch job ID (SID) for retrieving results later

Options

PropertyFieldDescription
Base URLoptBaseURLSplunk management API URL
CredentialsoptCredentialsSplunk Auth Token credentials
Earliest TimeoptEarliestTimeEarliest time boundary (e.g. -24h، -7d، 2024-01-01T00:00:00)
Execution ModeoptExecModeBlocking waits for completion، Normal returns immediately، Oneshot runs and returns results One of: blocking, normal, oneshot.
Latest TimeoptLatestTimeLatest time boundary (e.g. now، -1h، 2024-01-31T23:59:59)
Max ResultsoptMaxResultsMaximum number of results to return
Skip TLS VerificationoptSkipTLSSkip TLS certificate verification
Timeout (seconds)optTimeoutMaximum time in seconds to wait for search to complete

Requirements

  • A Client ID from this package's Connect node, unless you set credentials directly on this node.
  • Splunk Auth Token — Splunk authentication token for REST API access
    • value — Auth Token (password, required). Splunk authentication token from Settings > Tokens

Store these in a Vault and reference the vault item from the node, rather than typing the secret into the property.

Get Search Results · List Saved Searches · Run Saved Search

Elsewhere in the package: Connect · Disconnect · Send Event · List Indexes · Get Server Info · Toolkit

See also