When I insert an event and call the "services/search/jobs/export" REST endpoint, the XML that comes back is malformed and breaks XML parsing. There is another empty results document appended after the end of the document. Here is an example (with some valid result elements elided).
Any idea what could be causing this and how to work around it? We're running Splunk 4.2.3 on Windows 32.
<?xml version='1.0' encoding='UTF-8'?>
<results preview='0'>
<meta>
<fieldOrder>
<field>_cd</field>
<field>_indextime</field>
<field>_raw</field>
<field>_serial</field>
<field>_si</field>
<field>_sourcetype</field>
<field>_subsecond</field>
<field>_time</field>
<field>host</field>
<field>index</field>
<field>linecount</field>
<field>source</field>
<field>sourcetype</field>
<field>splunk_server</field>
</fieldOrder>
</meta>
<messages>
<msg type="DEBUG">base lispy: [ AND group ]</msg>
<msg type="DEBUG">search context: user="admin", app="search", bs-pathname="C:\splunk\etc"</msg>
</messages>
<result offset='0'>
<field k='_cd'>
<value><text>1:51</text></value>
</field>
<field k='_indextime'>
<value><text>1320939650</text></value>
</field>
<field k='_raw'><v xml:space='preserve' trunc='0'>1320939650437 event-type="Test" component="Job Controller" giraffe-server="wlon1907051257" <sg h='1'>group</sg>="cd290e81-75ca-4df6-b3e2-896d8085dc7b" sequence="1"</v></field>
<field k='_serial'>
<value><text>0</text></value>
</field>
<field k='_si'>
<value><text>wlon1907051257</text></value>
<value><text>main</text></value>
</field>
<field k='_sourcetype'>
<value><text>giraffe-audit</text></value>
</field>
<field k='_subsecond'>
<value><text>.437</text></value>
</field>
<field k='_time'>
<value><text>2011-11-10 15:40:50.437 GMT Standard Time</text></value>
</field>
<field k='host'>
<value><text>localhost</text></value>
</field>
<field k='index'>
<value><text>main</text></value>
</field>
<field k='linecount'>
<value><text>1</text></value>
</field>
<field k='source'>
<value><text>giraffe-localdev</text></value>
</field>
<field k='sourcetype'>
<value><text>giraffe-audit</text></value>
</field>
<field k='splunk_server'>
<value><text>wlon1907051257</text></value>
</field>
</result>
<result offset='1'>
....
</result>
</results>
<results preview='0'>
<meta>
<fieldOrder />
</meta>
</results>
<results preview='0'>
<meta>
<fieldOrder />
</meta>
</results>
<results preview='0'>
<meta>
<fieldOrder />
</meta>
</results>
Post to services/search/jobs and set the exec_mode parameter to "oneshot". That will return the results in a single document, not a malformed stream of multiple documents.
Post to services/search/jobs and set the exec_mode parameter to "oneshot". That will return the results in a single document, not a malformed stream of multiple documents.
I've upgraded to version 4.2.4 and still have the same issue.