I have a db connect input that I want to programatically activate and deactivate.
Following some docs I came up with this:
curl -k -H "authorization: Splunk XXXX" https://localhost:8089/servicesNS/nobody/splunk_app_db_connect/configs/conf-db_inputs/SIP_CAMIO_AUDIT_IN -d "disabled=1"
However db connect seems to ignore the change and keeps indexing data. Unless I access the /en-US/debug/refresh URL and manually refresh the whole server.
I decided to do a test and the following cURL works:
curl -k -H "authorization: Splunk XXXX" https://localhost:8089/servicesNS/nobody/Admin_Tools/configs/conf-macros/test_rest -d "disabled=1"
How can I disable/enable db connect inputs through REST?
Why does db_connect ignore conf updates through REST?
Edit:
I've tried accessing the following endpoint without luck aswell
curl -k -H "authorization: Splunk XXXX" -X POST https://localhost:8089/servicesNS/nobody/splunk_app_db_connect/configs/conf-db_inputs/_reload