All Apps and Add-ons

Splunk Cloud configs API endpoint using '| rest'

D2SI
Communicator

Hello there,

I am trying to understand how to work with | rest queries on Splunk Cloud.

For instance, using Enterprise version I am able to pull this endpoint to retrieve authorize configuration info:

| rest /servicesNS/-/-/configs/conf-authorize

This does not exist in Splunk Cloud.

Doc says it would be

/services/configs/conf-authorize

but it does not work, using '| rest' at least.

Is there a way to access configs endpoint using a '| rest' query on Splunk Cloud?

Thanks in advance for any hint!

0 Karma
1 Solution

DavidHourani
Super Champion

Hi @D2SI,

Did you have a look here :
https://answers.splunk.com/answers/470291/is-using-rest-api-not-allowed-with-splunk-cloud-tr.html

rest works exactly the same for Splunk Cloud and Enterprise. But cant be used in trial mode with Splunk Cloud.

Cheers,
David

View solution in original post

DavidHourani
Super Champion

Hi @D2SI,

Did you have a look here :
https://answers.splunk.com/answers/470291/is-using-rest-api-not-allowed-with-splunk-cloud-tr.html

rest works exactly the same for Splunk Cloud and Enterprise. But cant be used in trial mode with Splunk Cloud.

Cheers,
David

D2SI
Communicator

Wow, I did not think of that!

Thanks

0 Karma

DavidHourani
Super Champion

You're welcome 🙂

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...