<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Accessing Splunk Cloud Logs through Rest API in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Accessing-Splunk-Cloud-Logs-through-Rest-API/m-p/746618#M3822</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/310324"&gt;@krishna821&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most of the REST API endpoints you're likely using for on-premise are also available in Cloud.&lt;/P&gt;&lt;P&gt;The SplunkCloud REST API docs are at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/RESTREF/RESTprolog" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/RESTREF/RESTprolog&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You will need to ensure your egress IP is allow-listed on your Splunk Cloud environment as by default this is restricted. If you are not an admin on the Splunk Cloud platform then you will need to speak to your admin team to setup the allow-listing. For more information check out&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.3.2411/Config/ConfigureIPAllowList" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/9.3.2411/Config/ConfigureIPAllowList&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Note: I would recommend using Token authentication over user/password login. If your Splunk Cloud instance is using SAML/SSO authentication then you will need to use a token.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
    <pubDate>Tue, 20 May 2025 19:43:11 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2025-05-20T19:43:11Z</dc:date>
    <item>
      <title>Accessing Splunk Cloud Logs through Rest API</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Accessing-Splunk-Cloud-Logs-through-Rest-API/m-p/746583#M3820</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;This is Krishna and I have been some POC about accessing Splunk logs through Rest API's. I was successful in calling the Rest API's through Spunk Enterprise version but in my company we have Splunk Cloud and so unable to call Rest API's as how I was able to do in Splunk Enterprise edition. I would like to know the details of how I can call Splunk Rest API's for Cloud edition.&lt;/P&gt;&lt;P&gt;Below are my findings&lt;/P&gt;&lt;DIV&gt;On my local instance of Splunk when I hit the below url it lists all the services available&lt;/DIV&gt;&lt;DIV&gt;&lt;A class="" title="https://localhost:8089/services" href="https://localhost:8089/services" target="_blank" rel="noopener"&gt;https://localhost:8089/services&lt;/A&gt;(it asked me for admin credentials which I provided)&amp;nbsp;in which I am interested in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" title="https://localhost:8089/services/search/jobs" href="https://localhost:8089/services/search/jobs" target="_blank" rel="noopener"&gt;https://localhost:8089/services/&lt;/A&gt;&lt;STRONG&gt;&lt;A class="" title="https://localhost:8089/services/search/jobs" href="https://localhost:8089/services/search/jobs" target="_blank" rel="noopener"&gt;search/jobs&amp;nbsp;&lt;/A&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;so would like to call the similar ones for Cloud version&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Thanks in Advance.&lt;/DIV&gt;</description>
      <pubDate>Tue, 20 May 2025 18:14:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Accessing-Splunk-Cloud-Logs-through-Rest-API/m-p/746583#M3820</guid>
      <dc:creator>krishna821</dc:creator>
      <dc:date>2025-05-20T18:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing Splunk Cloud Logs through Rest API</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Accessing-Splunk-Cloud-Logs-through-Rest-API/m-p/746604#M3821</link>
      <description>&lt;P&gt;You could access SCP’s REST api, but you must enable it first. Here is instructions how to do it&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/RESTTUT/RESTandCloud" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/RESTTUT/RESTandCloud&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 18:45:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Accessing-Splunk-Cloud-Logs-through-Rest-API/m-p/746604#M3821</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-05-20T18:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing Splunk Cloud Logs through Rest API</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Accessing-Splunk-Cloud-Logs-through-Rest-API/m-p/746618#M3822</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/310324"&gt;@krishna821&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most of the REST API endpoints you're likely using for on-premise are also available in Cloud.&lt;/P&gt;&lt;P&gt;The SplunkCloud REST API docs are at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/RESTREF/RESTprolog" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/RESTREF/RESTprolog&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You will need to ensure your egress IP is allow-listed on your Splunk Cloud environment as by default this is restricted. If you are not an admin on the Splunk Cloud platform then you will need to speak to your admin team to setup the allow-listing. For more information check out&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.3.2411/Config/ConfigureIPAllowList" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/9.3.2411/Config/ConfigureIPAllowList&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Note: I would recommend using Token authentication over user/password login. If your Splunk Cloud instance is using SAML/SSO authentication then you will need to use a token.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 19:43:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Accessing-Splunk-Cloud-Logs-through-Rest-API/m-p/746618#M3822</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-05-20T19:43:11Z</dc:date>
    </item>
  </channel>
</rss>

