Reporting

Splunk REST API - add webhook using API but Splunk Web UI not showing it

gdbtek
New Member

has anyone successfully using Splunk API call /services/saved/searches/SEARCH_NAME(https://docs.splunk.com/Documentation/Splunk/9.2.1/RESTREF/RESTsearch#saved.2Fsearches.2F.7Bname.7D) to add a webhook for an existing Splunk report? I added action.webhook=1 , action.webhook.param.url=https://1234.com , and actions=pagerduty,webhook successfully through API but the Splunk UI does not show the webhook on UI (please see screenshot). Anyone has any idea what seem to be the problem?

 

 

curl \
        --data-urlencode 'action.webhook.param.url=https://1234.com' \
        --data-urlencode 'action.webhook=1' \
        --data-urlencode 'actions=pagerduty,webhook' \
        --data-urlencode 'output_mode=json' \
        --header "Authorization: Splunk A_TOKEN_HERE" \
        --insecure \
        --request 'POST' \
        --retry '12' \
        --retry-delay '5' \
        --silent \
        "https://localhost:8089/services/saved/searches/test-12345"

 

 

Screenshot 2024-05-20 at 5.32.11 PM.png

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

  Now On Demand  Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research ...

New in Splunk Observability Cloud: Automated Archiving for Unused Metrics

Automated Archival is a new capability within Metrics Management; which is a robust usage & cost optimization ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...