# New Search Result — Splunk

> Emit new events when a search returns results in Splunk. See the documentation

- Key: `splunk-new-search-result`
- Type: Trigger (Polling)
- Version: 0.0.1
- App: Splunk (`splunk`) — https://pipedream.com/apps/splunk.md
- This page (HTML): https://pipedream.com/apps/splunk/triggers/new-search-result
- Source: https://github.com/PipedreamHQ/pipedream/blob/master/components/splunk/sources/new-search-result/new-search-result.mjs

## Description

Emit new events when a search returns results in Splunk. [See the documentation](https://docs.splunk.com/Documentation/Splunk/9.4.1/RESTREF/RESTsearch#saved.2Fsearches)

## Props

| Prop | Type | Required | Description |
|---|---|---|---|
| `timer` | `$.interface.timer` | Yes | Timer |

## Returns

Events emitted by Splunk.

## Run it

**TypeScript**

```ts
import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const deployed = await pd.triggers.deploy({
  id: "splunk-new-search-result",
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  configuredProps: {
    splunk: { authProvisionId: "apn_xxxxxxx" },
    timer: { "intervalSeconds": 900 },
  },
  webhookUrl: "https://example.com/webhooks/splunk",
})

console.log(deployed.id)
```

**cURL**

```bash
curl -X POST https://api.pipedream.com/v1/connect/{project_id}/triggers/deploy \
  -H "Content-Type: application/json" \
  -H "X-PD-Environment: production" \
  -H "Authorization: Bearer {access_token}" \
  -d '{
    "external_user_id": "{external_user_id}",
    "id": "splunk-new-search-result",
    "webhook_url": "https://example.com/webhooks/splunk",
    "configured_props": {
      "splunk": { "authProvisionId": "apn_xxxxxxx" },
      "timer": { "intervalSeconds": 900 }
    }
  }'
```

**MCP**

MCP servers expose Splunk actions as on-demand tools.

New Search Result is an event source, so your application deploys it with the Connect SDK or API and then either receives each event at a webhook URL or retrieves events on demand with the trigger events API.

## Event delivery

Every event is sent to the HTTP endpoint you choose when you deploy the source. Or: no webhook required — your app or agent can fetch recent events from the [trigger events API](https://pipedream.com/docs/connect/api-reference/list-trigger-events.md) instead.

---

- App: https://pipedream.com/apps/splunk.md · All apps: https://pipedream.com/apps
