I am trying to understand how to work with | rest queries on Splunk Cloud.
For instance, using Enterprise version I am able to pull this endpoint to retrieve authorize configuration info:
| rest /servicesNS/-/-/configs/conf-authorize
This does not exist in Splunk Cloud.
Doc says it would be
but it does not work, using '| rest' at least.
Is there a way to access configs endpoint using a '| rest' query on Splunk Cloud?
Thanks in advance for any hint!
Did you have a look here :
rest works exactly the same for Splunk Cloud and Enterprise. But cant be used in trial mode with Splunk Cloud.