Using the Splunk REST API, i see that XML response will return search syntax errors or warnings. if you select output_mode="csv" or output_mode="json" and the search had a syntax error, it simply finishes quickly and returns zero results.
Is there a way to change this behavior so that an error in syntax will return an error message instead of just sending back 0 results? I'd like to use JSON and not have to overhaul to support XML.
Searching API documents, I keep coming up empty.