Splunk Enterprise Security

Splunk Enterprise Security: API 'notable_update' error - Invalid method for this endpoint

Explorer

Hello!

I'm trying to query the notable_update service via api (.../services/notable_update)
and get error of - "Invalid method for this endpoint"

My user has the admin role.
I'm authenticating Splunk with SAML.

  1. I have granted 'edit_notable_events' capability both or ess_user and ess_analyst roles on Splunk Enterprise Security configuration.
  2. I have granted my user both ess_user and ess_analyst roles.

Thanks

0 Karma

New Member

Your using the wrong method
Probably get instead of post ?

0 Karma

Explorer

its just a simple as that -
https://:8089/services/notable_update

both web and curl

0 Karma

SplunkTrust
SplunkTrust

@OBsecurity If your problem is resolved, please accept the answer to help future readers.

---
If this reply helps you, an upvote would be appreciated.
0 Karma

Explorer

no problem

0 Karma