Getting Data In

Splunk and Postman

jwkriewall
Observer

I have a question regarding the Splunk and Postman interaction. I've set up a Splunk instance inside a Linux virtual machine. I am able to use the curl command to access Splunk endpoints in the VM. Doing so returns an SID which I can then use to get Splunk data.

However, I am having a hard time retrieving the SID from Postman. When I try to connect to the API I am met with an "Unauthorized" message (pic attached). I am using Basic Auth and inputting an admin username and PW. 

Any ideas on what to do? What piece am I missing?

jwkriewall_0-1621860652590.png

jwkriewall_1-1621860721079.png

 

 

Labels (1)
0 Karma

Marco
Communicator

For step 1  you are supposed to use this Url: https://api.splunk.com/2.0/rest/login/splunk

 

Correct Url.PNG

 

0 Karma

jwkriewall
Observer

Before this suggestion comes in, I've already disabled SSL Certification on Postman!

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...