Splunk Enterprise Security

ES Incident Review Restapi

lpoko
Engager

Does Splunk Enterprise provides any API to retrieve or modify Incidents by RestAPI?

Example:

  • Get Incident information 
  • Change Incident Status 
  • Change Incident Severity 
  • Change Incident Owner
  • Add Tag to incident
Labels (1)
0 Karma
1 Solution

meetmshah
Contributor

Hello @lpoko,

You can use "/services/notable_update"  from here - for most tasks https://docs.splunk.com/Documentation/ES/latest/API/NotableEventAPIreference

 

Please accept the solution if this helps!

View solution in original post

meetmshah
Contributor

Hello @lpoko,

You can use "/services/notable_update"  from here - for most tasks https://docs.splunk.com/Documentation/ES/latest/API/NotableEventAPIreference

 

Please accept the solution if this helps!

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...