Splunk Search

Splunk Search

Certified
Enterprise Edition

Execute a Splunk search query

Runs a Splunk SPL query against the management API, polls until the job completes, and stores paginated results as a JSON array in Kestra internal storage.

yaml
type: io.kestra.plugin.ee.splunk.events.Search

Search Splunk for recent events

yaml
id: splunk_search
namespace: company.team

tasks:
  - id: search
    type: io.kestra.plugin.ee.splunk.events.Search
    host: michmed.splunkcloud.com
    token: "{{ secret('SPLUNK_TOKEN') }}"
    query: 'search index=main | head 100'
Properties

Splunk host

Hostname of the Splunk endpoint (e.g. michmed.splunkcloud.com)

SPL query

Splunk search query in SPL (Search Processing Language)

Default10000

Batch size

Results per paginated fetch request; defaults to 10000

Default3600

Max wait (seconds)

Maximum seconds to wait for job completion before timing out; defaults to 3600

HTTP client options

Optional HTTP client configuration — timeouts, TLS, proxy, etc.

Definitions
allowFailedbooleanstring
Defaultfalse

If true, allow a failed response code (response code >= 400)

allowedResponseCodesarray
SubTypeinteger

List of response code allowed for this request

auth

The authentication to use.

type*Requiredobject
passwordstring

The password for HTTP basic authentication.

usernamestring

The username for HTTP basic authentication.

type*Requiredobject
tokenstring

The token for bearer token authentication.

type*Requiredobject
passwordstring

The password for HTTP Digest authentication.

usernamestring

The username for HTTP Digest authentication.

basicAuthPasswordDeprecatedstring

The password for HTTP basic authentication. Deprecated, use auth property with a BasicAuthConfiguration instance instead.

basicAuthUserDeprecatedstring

The username for HTTP basic authentication. Deprecated, use auth property with a BasicAuthConfiguration instance instead.

connectTimeoutDeprecatedstring
Formatduration

The time allowed to establish a connection to the server before failing.

connectionPoolIdleTimeoutDeprecatedstring
Formatduration

The time an idle connection can remain in the client's connection pool before being closed.

defaultCharsetstring
DefaultUTF-8

The default charset for the request.

enabledTcpExtendedKeepAlivebooleanstring
Defaulttrue

Whether to enable TCP Keep-Alive extended socket options (TCP_KEEPIDLE, TCP_KEEPINTERVAL, TCP_KEEPCOUNT).

Set to false when running on Windows workers, as these extended socket options are not supported by the Windows JDK and will cause connection failures.

followRedirectsbooleanstring
Defaulttrue

Whether redirects should be followed automatically.

logLevelDeprecatedstring
Possible Values
ALLTRACEDEBUGINFOWARNERROROFFNOT_SPECIFIED

The log level for the HTTP client.

logsarray
SubTypestring
Possible Values
REQUEST_HEADERSREQUEST_BODYRESPONSE_HEADERSRESPONSE_BODY

The enabled log.

maxContentLengthDeprecatedinteger

The maximum content length of the response.

proxy

The proxy configuration.

addressstring

The address of the proxy server.

passwordstring

The password for proxy authentication.

portintegerstring

The port of the proxy server.

typestring
DefaultDIRECT
Possible Values
DIRECTHTTPSOCKS

The type of proxy to use.

usernamestring

The username for proxy authentication.

proxyAddressDeprecatedstring

The address of the proxy server.

proxyPasswordDeprecatedstring

The password for proxy authentication.

proxyPortDeprecatedinteger

The port of the proxy server.

proxyTypeDeprecatedstring
Possible Values
DIRECTHTTPSOCKS

The type of proxy to use.

proxyUsernameDeprecatedstring

The username for proxy authentication.

readIdleTimeoutDeprecatedstring
Formatduration

The time allowed for a read connection to remain idle before closing it.

readTimeoutDeprecatedstring
Formatduration

The maximum time allowed for reading data from the server before failing.

ssl

The SSL request options

insecureTrustAllCertificatesbooleanstring

Whether to disable checking of the remote SSL certificate.

Only applies if no trust store is configured. Note: This makes the SSL connection insecure and should only be used for testing. If you are using a self-signed certificate, set up a trust store instead.

timeout

The timeout configuration.

connectTimeoutstring

The time allowed to establish a connection to the server before failing.

readIdleTimeoutstring
DefaultPT5M

The time allowed for a read connection to remain idle before closing it.

DefaultJSON
Possible Values
JSONJSON_ROWSJSON_COLSCSVXMLRAW

Output mode

Format of the search results; defaults to JSON

Password

Password for Basic auth; ignored when token is set

Reference (ref) of the pluginDefaults to apply to this task.

Default2

Poll interval (seconds)

Seconds between job-status poll requests; defaults to 2

Default8089

Management port

Splunk management API port; defaults to 8089

Defaulthttps

URL scheme

URL scheme — http or https; defaults to https

Bearer token

Token for Bearer auth; takes precedence over username/password

Username

Username for Basic auth; ignored when token is set

Result count

Total number of results fetched from the search job

Search ID

Splunk search job ID (SID)

Formaturi

Results URI

URI of the JSON array file in Kestra internal storage

Total number of search results fetched