Run Search
Runs a search in Splunk.
This node is also exposed as an AI Agent tool.
This node has 1 input port and 1 output port.
Common Properties
Every node shares these.
- Name — the node's display name on the canvas.
- Color — the node's colour on the canvas.
- Delay Before (sec) — wait this long before the node runs.
- Delay After (sec) — wait this long after the node runs.
- Continue On Error — carry on instead of failing the flow. Defaults to false.
info
When Continue On Error is true the error is not raised at all, so a Catch node will not see it either.
Inputs
| Property | Field | Description |
|---|---|---|
| Client ID | inClientID | Client ID from Connect node |
| Search Query | inQuery | SPL search query (e.g. search index |
Outputs
| Property | Field | Description |
|---|---|---|
| Result Count | outCount | Number of results returned |
| Results | outResults | Search results as array of objects |
| Search ID | outSID | Search job ID (SID) for retrieving results later |
Options
| Property | Field | Description |
|---|---|---|
| Base URL | optBaseURL | Splunk management API URL |
| Credentials | optCredentials | Splunk Auth Token credentials |
| Earliest Time | optEarliestTime | Earliest time boundary (e.g. -24h، -7d، 2024-01-01T00:00:00) |
| Execution Mode | optExecMode | Blocking waits for completion، Normal returns immediately، Oneshot runs and returns results One of: blocking, normal, oneshot. |
| Latest Time | optLatestTime | Latest time boundary (e.g. now، -1h، 2024-01-31T23:59:59) |
| Max Results | optMaxResults | Maximum number of results to return |
| Skip TLS Verification | optSkipTLS | Skip TLS certificate verification |
| Timeout (seconds) | optTimeout | Maximum time in seconds to wait for search to complete |
Requirements
- A Client ID from this package's Connect node, unless you set credentials directly on this node.
- Splunk Auth Token — Splunk authentication token for REST API access
value— Auth Token (password, required). Splunk authentication token from Settings > Tokens
Store these in a Vault and reference the vault item from the node, rather than typing the secret into the property.
Related nodes
Get Search Results · List Saved Searches · Run Saved Search
Elsewhere in the package: Connect · Disconnect · Send Event · List Indexes · Get Server Info · Toolkit
See also
- Splunk — every node in this package
- Message object — how properties read values from
msg - Handling failure — Continue On Error, Catch and retries