Getting Data In

Can you make .conf changes with the rest API?

Log_wrangler
Builder

Has anyone used the rest API to successfully edit a conf file?

I understand there are 3 methods GET, POST, DELETE.
I understand one can manipulate searches but I am unfamiliar with managing objects and configurations with the API.

Any advice or examples would be awesome.

Thank you

Tags (3)
0 Karma
1 Solution

renjith_nair
SplunkTrust
SplunkTrust

@Log_wrangler,

You can edit conf with rest API

For e.g.

curl -k -u admin:pass https://localhost:8089/servicesNS/nobody/search/configs/conf-props \
    -d name=myweblogs \
    -d CHARSET=UTF-8 \
    -d SHOULD_LINEMERGE=false

In the above, if the stanza myweblogs does not exist, then it creates a new one and if it exists, it updates it with the value you provided.

Detailed documentation is available in http://docs.splunk.com/Documentation/Splunk/latest/RESTTUT/RESTconfigurations

Happy Splunking!

View solution in original post

renjith_nair
SplunkTrust
SplunkTrust

@Log_wrangler,

You can edit conf with rest API

For e.g.

curl -k -u admin:pass https://localhost:8089/servicesNS/nobody/search/configs/conf-props \
    -d name=myweblogs \
    -d CHARSET=UTF-8 \
    -d SHOULD_LINEMERGE=false

In the above, if the stanza myweblogs does not exist, then it creates a new one and if it exists, it updates it with the value you provided.

Detailed documentation is available in http://docs.splunk.com/Documentation/Splunk/latest/RESTTUT/RESTconfigurations

Happy Splunking!

serjandrosov
Path Finder
0 Karma
Get Updates on the Splunk Community!

BSides Splunk 2022 - The Call for Papers is now Open!

TLDR; Main Site: https://bsidessplunk.com CFP Site: https://bsidessplunk.com/cfp CFP Opens: December 15th, ...

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...