
Splunk Search
CertifiedEnterprise EditionExecute a Splunk search query
Splunk Search
Execute a Splunk search query
Runs a Splunk SPL query against the management API, polls until the job completes, and stores paginated results as a JSON array in Kestra internal storage.
type: io.kestra.plugin.ee.splunk.events.SearchExamples
Search Splunk for recent events
id: splunk_search
namespace: company.team
tasks:
- id: search
type: io.kestra.plugin.ee.splunk.events.Search
host: michmed.splunkcloud.com
token: "{{ secret('SPLUNK_TOKEN') }}"
query: 'search index=main | head 100'
Properties
host *Requiredstring
Splunk host
Hostname of the Splunk endpoint (e.g. michmed.splunkcloud.com)
query *Requiredstring
SPL query
Splunk search query in SPL (Search Processing Language)
batchSize integerstring
10000Batch size
Results per paginated fetch request; defaults to 10000
maxWaitSeconds integerstring
3600Max wait (seconds)
Maximum seconds to wait for job completion before timing out; defaults to 3600
options Non-dynamic
HTTP client options
Optional HTTP client configuration — timeouts, TLS, proxy, etc.
io.kestra.core.http.client.configurations.HttpConfiguration
falseIf true, allow a failed response code (response code >= 400)
List of response code allowed for this request
The authentication to use.
io.kestra.core.http.client.configurations.BasicAuthConfiguration
The password for HTTP basic authentication.
The username for HTTP basic authentication.
io.kestra.core.http.client.configurations.BearerAuthConfiguration
The token for bearer token authentication.
io.kestra.core.http.client.configurations.DigestAuthConfiguration
The password for HTTP Digest authentication.
The username for HTTP Digest authentication.
The password for HTTP basic authentication. Deprecated, use auth property with a BasicAuthConfiguration instance instead.
The username for HTTP basic authentication. Deprecated, use auth property with a BasicAuthConfiguration instance instead.
durationThe time allowed to establish a connection to the server before failing.
durationThe time an idle connection can remain in the client's connection pool before being closed.
UTF-8The default charset for the request.
java.nio.charset.Charset
trueWhether to enable TCP Keep-Alive extended socket options (TCP_KEEPIDLE, TCP_KEEPINTERVAL, TCP_KEEPCOUNT).
Set to false when running on Windows workers, as these extended socket options are not supported by the Windows JDK and will cause connection failures.
trueWhether redirects should be followed automatically.
ALLTRACEDEBUGINFOWARNERROROFFNOT_SPECIFIEDThe log level for the HTTP client.
REQUEST_HEADERSREQUEST_BODYRESPONSE_HEADERSRESPONSE_BODYThe enabled log.
The maximum content length of the response.
The proxy configuration.
io.kestra.core.http.client.configurations.ProxyConfiguration
The address of the proxy server.
The password for proxy authentication.
The port of the proxy server.
DIRECTDIRECTHTTPSOCKSThe type of proxy to use.
The username for proxy authentication.
The address of the proxy server.
The password for proxy authentication.
The port of the proxy server.
DIRECTHTTPSOCKSThe type of proxy to use.
The username for proxy authentication.
durationThe time allowed for a read connection to remain idle before closing it.
durationThe maximum time allowed for reading data from the server before failing.
The SSL request options
io.kestra.core.http.client.configurations.SslOptions
Whether to disable checking of the remote SSL certificate.
Only applies if no trust store is configured. Note: This makes the SSL connection insecure and should only be used for testing. If you are using a self-signed certificate, set up a trust store instead.
The timeout configuration.
io.kestra.core.http.client.configurations.TimeoutConfiguration
The time allowed to establish a connection to the server before failing.
PT5MThe time allowed for a read connection to remain idle before closing it.
outputMode string
JSONJSONJSON_ROWSJSON_COLSCSVXMLRAWOutput mode
Format of the search results; defaults to JSON
password string
Password
Password for Basic auth; ignored when token is set
pluginDefaultsRef Non-dynamicstring
Reference (ref) of the pluginDefaults to apply to this task.
pollIntervalSeconds integerstring
2Poll interval (seconds)
Seconds between job-status poll requests; defaults to 2
port string
8089Management port
Splunk management API port; defaults to 8089
scheme string
httpsURL scheme
URL scheme — http or https; defaults to https
token string
Bearer token
Token for Bearer auth; takes precedence over username/password
username string
Username
Username for Basic auth; ignored when token is set
Outputs
resultCount integer
Result count
Total number of results fetched from the search job
sid string
Search ID
Splunk search job ID (SID)
uri string
uriResults URI
URI of the JSON array file in Kestra internal storage
Metrics
results.count counter
Total number of search results fetched