Splunk Enterprise Security

Splunk Enterprise Security: API 'notable_update' error - Invalid method for this endpoint

OBsecurity
Explorer

Hello!

I'm trying to query the notable_update service via api (.../services/notable_update)
and get error of - "Invalid method for this endpoint"

My user has the admin role.
I'm authenticating Splunk with SAML.

  1. I have granted 'edit_notable_events' capability both or ess_user and ess_analyst roles on Splunk Enterprise Security configuration.
  2. I have granted my user both ess_user and ess_analyst roles.

Thanks

0 Karma

ArikSiem
New Member

Your using the wrong method
Probably get instead of post ?

0 Karma

OBsecurity
Explorer

its just a simple as that -
https://:8089/services/notable_update

both web and curl

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@OBsecurity If your problem is resolved, please accept the answer to help future readers.

---
If this reply helps you, Karma would be appreciated.
0 Karma

OBsecurity
Explorer

no problem

0 Karma
Get Updates on the Splunk Community!

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...

Explore the Latest Educational Offerings from Splunk (November Releases)

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...