All Apps and Add-ons

TA-WebTools - Syntax question

JoeCallen
Explorer

I have reviewed the curl command syntax in the details section of the Add-on download page but was not able to discern how pass the following to the "| curl" command

1) How can I pass the equivalent of:   '-k" or "--insecure'  ?
2) How do I pass 2 headers in the same command line ? 
From the LINUX prompt, my command looks like this: 
 
curl -X POST -H "Content-Type: application/json" -H "UUID: e42eed31-65bb-4283-ad05-33f18da75513" -k "https://abc.com/X1"  -d "{ lots of data }"

Labels (1)
0 Karma
1 Solution

schose
Builder

Hi Joe,

yes, you can download the app, patch it and upload it as a private app.

Cheers,

Andreas

View solution in original post

schose
Builder

Hi Joe,

there is a command documentation in default/searchbnf.conf

[curl-command]
syntax = CURL [choice:URI=<uri> OR URIFIELD=<urifield>] [optional: METHOD=<GET|PATCH|POST|PUT|DELETE> VERIFYSSL=<TRUE|FALSE> DATAFIELD=<field_name> DATA=<data> HEADERFIELD=<json_header_field_name> HEADERS=<json_header> USER=<user> PASS=<password> DEBUG=<true|false> SPLUNKAUTH=<true|false> SPLUNKPASSWDNAME=<username_in_passwordsconf> SPLUNKPASSWDCONTEXT=<appcontext (optional)> TIMEOUT=<float>]

-k = "VERIFYSSL=FALSE"
headers="{\"content-type\":\"application/json\"}"

best regards,

Andreas

0 Karma

JoeCallen
Explorer

Andreas, thank for the quick response.  

Unfortunately, I am using Splunk Cloud, and I see in your "curl.py" file that VERIFYSSL is "Forced to be True for Splunk Cloud Compatibility".

So, while "curl -k" works from the LINUX command line on my Splunk server,  in Splunk SPL the "| curl verifyssl=false" is overridden in the add-on's python code.

Is there any way to override ??? If not, I will have to find another way to do this, as I am constrained by my environment.

0 Karma

schose
Builder

Hi Joe,

yes, you can download the app, patch it and upload it as a private app.

Cheers,

Andreas

Get Updates on the Splunk Community!

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco &#43; Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...