Getting Data In

How to enable rest-api?

rajanshrivastav
Path Finder

Hi Team,

I'm running Splunk on AWS ec2 instance backed by AWS ALB.
I've created target group for port 80,443 & 8089 for splunk. Security groups & network ACL are already opened for these ports.
But whenever I do "curl -k http://localhost:8089/en-us",
it says -- "curl: (56) Recv failure: Connection reset by peer"

I'm accessing it as a root user , also I've admin credentials as well.

Please let me know how I can access this port, I've a requirement to enable rest-api. I checked for other articles but I didn't find any satisfactory answers. I got to know that rest-api works for everyone, but in my case it is not working.

Please help me enabling rest-api features.

Thanks,

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi rajanshrivastav786,

But whenever I do "curl -k
http://localhost:8089/en-us",
Your problem is that you are using port 8089 AND http, the management port and therefore the REST API uses SSL by default.

Just use curl -k https://localhost:8089/ instead and it works.

cheers, MuS

inventsekar
SplunkTrust
SplunkTrust

As per my knowledge, there is no enable/disable for rest API.
(Maybe, roles/capabilities issue can occur)

To verify, Simply run...(replace the admin:changeme to your username:password)

curl -k -u admin:changeme https://localhost:8089/services/search/jobs --data-urlencode 'search=search index="_internal" | head 1'

0 Karma

rajanshrivastav
Path Finder

After running above command, it is showing following result-

1536009195.1426

0 Karma

rajanshrivastav
Path Finder

"

1536009195.1426

"

0 Karma

rajanshrivastav
Path Finder

Blockquote

1536009195.1426

Blockquote

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...