Splunk REST API error handling with ouput_mode=json OR output_mode=csv

Viewed 56

Using the Splunk REST API, i see that XML response will return search syntax errors or warnings. if you select output_mode="csv" or output_mode="json" and the search had a syntax error, it simply finishes quickly and returns zero results.

Is there a way to change this behavior so that an error in syntax will return an error message instead of just sending back 0 results? I'd like to use JSON and not have to overhaul to support XML.

Searching API documents, I keep coming up empty.

0 Answers
Related