Splunk Enterprise

How to use REST API in Splunk?

rendie
Path Finder

Hello,

I have a little trouble with using REST API in Splunk via curl and postman.

I have my own Splunk application with a python script which is available by link http://splunk:8000/en-US/splunkd/__raw/services/appname/pyscript.
And I wanna get access to this file via PostMan or Curl. In the first step, I created sessionsKey - successful.

But when I want to use this key in the header "Authorization: Splunk <key>" via POST/GET then via curl I see "303 see other", and via postman - "Splunk relies on JavaScript to function properly. Please enable JavaScript and then refresh the page to login."

 

Where I wrong?

0 Karma

charan001
Loves-to-Learn Lots

Hi Rendie ,

I know i am late to the thread , is this below issue resolved? if so could you please let me know the resolution.

 

Thanks in Advance

0 Karma

rendie
Path Finder

Hi,

Alas, I did not find the correct solution for this problem. I got around the problem by using cookies in requests.

1. Made a login through the browser
2. Got the cookie and used it in Python script

Alas, this is the only way that worked for me.

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...