execute_saved_search
Execute saved Splunk searches by name with time overrides and mode selection. Get immediate results or track progress for large datasets while respecting user permissions.
Instructions
Run a saved search by name with optional time overrides and mode selection. Use this to execute existing reports/automations quickly. Choose 'oneshot' for immediate results or 'job' for progress tracking and large result sets.\n\nOutputs: results list (capped by max_results), mode used, timing, and job id (if job).\nSecurity: execution and results are constrained by the authenticated user's permissions.
Input Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | ||
| earliest_time | No | ||
| latest_time | No | ||
| mode | No | oneshot | |
| max_results | No | ||
| app | No | ||
| owner | No |