Splunk Enterprise

Creation/modification of Splunk configuration objects via REST api in Splunk cloud

koshyk
Super Champion

I've almost created  a  framework to update  Splunk configuration  items for Search Heads   (transforms, props, savedsearches) etc and Create NEW apps via Splunk REST api. This works well in Standalone SH & SH cluster.

Anyone  know if there are restrictions/capability  restrictions kept  in place for Splunk cloud offering?

ie in Cloud offering

- Can  I  create a  new App  via Rest api ?

- Can i create/modify configuration items remotely?

Labels (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

You can't create apps using the API and configuration support is limited.  See https://docs.splunk.com/Documentation/SplunkCloud/8.2.2105/RESTTUT/RESTandCloud

---
If this reply helps you, Karma would be appreciated.
0 Karma

koshyk
Super Champion

that's really not good.

 >> is restricted from performing the following types of tasks... Installing apps and modifying app configurations

almost cancels the whole point of automation then? How do you guys control the search-time and custom TA configurations in Splunk cloud & Version control them? Manually upload them and give to  Splunk support?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

There's little need to have Splunk support do it for you.  Update your apps off-line making sure you increment the version number in app.conf.  Then upload the app(s) to your Splunk Cloud search head.  Once they pass vetting you can install them and Splunk Cloud will deploy them to the right instance(s).

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...