Getting Data In

Sending HTTP DELETE request using splunk's 'rest' command

paramagurukarth
Builder

Please let me know if there any way to send a HTTP request to splunk REST end point using splunk's rest (http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/Rest) command with HTTP DELETE method

Tags (2)
0 Karma

paramagurukarth
Builder

Splunk REST will return xml in ODATA format...
For example, https://localhost:8089/servicesNS/-/search/saved/searches

This search will return list of saved searches..
One **** tag for each saved searches
Each entry tag contains child tags **** (More than one) , these tag contains URLs related to that particular saved search and the relation is defined by the attribute "rel"..
Pick the one with "rel" as "remove" and send a ajax request with http_method DELETE or use any REST Clients (Post Man REST client plugin for chrome).. you can remove it

0 Karma

gwobben
Communicator

The rest command in Splunk can only do GET requests

Patient
Path Finder

Hi,
If I've understood what you need, I will like to let You know that you can set this stanza [:] in the restmap.conf.spec file. Applicable to all REST stanzas
Stanza definitions below may supply additional information for these.

   [<rest endpoint name>:<endpoint description string>]
 * match=<path> to  Specify the URI that calls the handler.
 * capability.<post|delete|get|put>=<capabilityName>
 * Depending on the HTTP method, check capabilitieson the authenticated session user.
 * If you use 'capability.post|delete|get|put,' then the associated
   method is checked

`

0 Karma

gwobben
Communicator

I downvoted this post because not related to the question

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...