All Apps and Add-ons

Splunk Cloud configs API endpoint using '| rest'

D2SI
Communicator

Hello there,

I am trying to understand how to work with | rest queries on Splunk Cloud.

For instance, using Enterprise version I am able to pull this endpoint to retrieve authorize configuration info:

| rest /servicesNS/-/-/configs/conf-authorize

This does not exist in Splunk Cloud.

Doc says it would be

/services/configs/conf-authorize

but it does not work, using '| rest' at least.

Is there a way to access configs endpoint using a '| rest' query on Splunk Cloud?

Thanks in advance for any hint!

0 Karma
1 Solution

DavidHourani
Super Champion

Hi @D2SI,

Did you have a look here :
https://answers.splunk.com/answers/470291/is-using-rest-api-not-allowed-with-splunk-cloud-tr.html

rest works exactly the same for Splunk Cloud and Enterprise. But cant be used in trial mode with Splunk Cloud.

Cheers,
David

View solution in original post

DavidHourani
Super Champion

Hi @D2SI,

Did you have a look here :
https://answers.splunk.com/answers/470291/is-using-rest-api-not-allowed-with-splunk-cloud-tr.html

rest works exactly the same for Splunk Cloud and Enterprise. But cant be used in trial mode with Splunk Cloud.

Cheers,
David

D2SI
Communicator

Wow, I did not think of that!

Thanks

0 Karma

DavidHourani
Super Champion

You're welcome 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...