All Apps and Add-ons

Splunk Cloud configs API endpoint using '| rest'

D2SI
Communicator

Hello there,

I am trying to understand how to work with | rest queries on Splunk Cloud.

For instance, using Enterprise version I am able to pull this endpoint to retrieve authorize configuration info:

| rest /servicesNS/-/-/configs/conf-authorize

This does not exist in Splunk Cloud.

Doc says it would be

/services/configs/conf-authorize

but it does not work, using '| rest' at least.

Is there a way to access configs endpoint using a '| rest' query on Splunk Cloud?

Thanks in advance for any hint!

0 Karma
1 Solution

DavidHourani
Super Champion

Hi @D2SI,

Did you have a look here :
https://answers.splunk.com/answers/470291/is-using-rest-api-not-allowed-with-splunk-cloud-tr.html

rest works exactly the same for Splunk Cloud and Enterprise. But cant be used in trial mode with Splunk Cloud.

Cheers,
David

View solution in original post

DavidHourani
Super Champion

Hi @D2SI,

Did you have a look here :
https://answers.splunk.com/answers/470291/is-using-rest-api-not-allowed-with-splunk-cloud-tr.html

rest works exactly the same for Splunk Cloud and Enterprise. But cant be used in trial mode with Splunk Cloud.

Cheers,
David

D2SI
Communicator

Wow, I did not think of that!

Thanks

0 Karma

DavidHourani
Super Champion

You're welcome 🙂

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...