All Apps and Add-ons

TA-Webtools - Why am I getting the error CURL invalid json in request?

glouka_tp
Loves-to-Learn Everything

Hello,

I'm trying to run the following:

 

| makeresults count=1

| eval data = "{\"something\":\"something\",\"something\":\"something\",\"something\":\"something\"}"

| eval header = "{\"header-api-key\":\"something\"}"

| curl  method=post  uri="https://api.something/v2" headerfield=header  data=data debug=t verifyssl=false

| table  *

 

and I'm getting

"{"status": "error", "result": "Invalid json format in the request".

Also I tried to add

"{\"content-type\":\"application/json\"}" like :

 

| eval header = "{"{\"content-type\":\"application/json\"}",\"header-api-key\":\"something\"}"

 

but I get the some error. Note that I have the latest version of TA-webtools

Anyone has any suggestions? 

Thank in advance 

Labels (1)
Tags (4)
0 Karma

gjanders
SplunkTrust
SplunkTrust

Try datafield=data

 

| curl  method=post  uri="https://api.something/v2" headerfield=header  datafield=data debug=t verifyssl=false

 

0 Karma

glouka_tp
Loves-to-Learn Everything

Same error as before

0 Karma

gjanders
SplunkTrust
SplunkTrust

I've used nearly identical settings and it works.

 

If you hit same endpoint using the actual curl CLI tool do you see the same issue?

0 Karma

glouka_tp
Loves-to-Learn Everything

Thank for your reply gjanders.

I don't have any error with the actual curl. The response is in a json format.

Find below the actual curl:

curl -X POST -d @option.txt -k -H "header-api-key:<API KEY>" "https://api.something/v2"

 

option.txt file:

{

"something": "something",

"something": "something",

"something": "something"

}

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...