問題文
An engineer wants a nightly external job to run a search on the Splunk platform and collect the results. Which sequence of REST interactions accomplishes that?
選択肢
- Get the saved searches endpoint to read the search string, run it locally with a command line tool, and post the results back to a summary index and that report then reads that summary index.
- Put the search into the configuration endpoint so it is registered as a scheduled search, then get the results from the same endpoint after the schedule has passed, which keeps the whole exchange to two calls.
- Post the search to the search jobs endpoint and read the results directly from the response body, because the endpoint blocks until the search has completed and then returns the rows in the same call to the calling client.
- Post the search to the search jobs endpoint, read the identifier that comes back, poll the job until it reports that it has finished, and then request the results for that identifier.