All Apps and Add-ons

Splunk Cloud configs API endpoint using '| rest'

D2SI
Communicator

Hello there,

I am trying to understand how to work with | rest queries on Splunk Cloud.

For instance, using Enterprise version I am able to pull this endpoint to retrieve authorize configuration info:

| rest /servicesNS/-/-/configs/conf-authorize

This does not exist in Splunk Cloud.

Doc says it would be

/services/configs/conf-authorize

but it does not work, using '| rest' at least.

Is there a way to access configs endpoint using a '| rest' query on Splunk Cloud?

Thanks in advance for any hint!

0 Karma
1 Solution

DavidHourani
Super Champion

Hi @D2SI,

Did you have a look here :
https://answers.splunk.com/answers/470291/is-using-rest-api-not-allowed-with-splunk-cloud-tr.html

rest works exactly the same for Splunk Cloud and Enterprise. But cant be used in trial mode with Splunk Cloud.

Cheers,
David

View solution in original post

DavidHourani
Super Champion

Hi @D2SI,

Did you have a look here :
https://answers.splunk.com/answers/470291/is-using-rest-api-not-allowed-with-splunk-cloud-tr.html

rest works exactly the same for Splunk Cloud and Enterprise. But cant be used in trial mode with Splunk Cloud.

Cheers,
David

D2SI
Communicator

Wow, I did not think of that!

Thanks

0 Karma

DavidHourani
Super Champion

You're welcome 🙂

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...