- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk Enterprise Security: API 'notable_update' error - Invalid method for this endpoint

OBsecurity
Explorer
03-27-2018
06:52 AM
Hello!
I'm trying to query the notable_update service via api (.../services/notable_update)
and get error of - "Invalid method for this endpoint"
My user has the admin role.
I'm authenticating Splunk with SAML.
- I have granted 'edit_notable_events' capability both or ess_user and ess_analyst roles on Splunk Enterprise Security configuration.
- I have granted my user both ess_user and ess_analyst roles.
Thanks
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ArikSiem
New Member
04-01-2018
01:11 PM
Your using the wrong method
Probably get instead of post ?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

OBsecurity
Explorer
04-02-2018
01:28 PM
its just a simple as that -
https://:8089/services/notable_update
both web and curl
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
04-02-2018
04:31 PM
@OBsecurity If your problem is resolved, please accept the answer to help future readers.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

OBsecurity
Explorer
04-03-2018
06:46 AM
no problem
