Skip to main content
Create a new Search Job based on a search query string, and get the search results. Note: If the search time reaches the action timeout limit, the action will return a timeout error and the search job ID. You can then use the returned SID with actions like Get Search Job By ID to check the job’s status (available under the entry.content.dispatchState key). Once the status is DONE, you can retrieve the results using the Get Search Job Results action.

Basic Parameters

Advanced Parameters

Example Output

Workflow Library Example

Run Search with Splunk and Send Results Via Email
Workflow LibraryPreview this Workflow on desktop