Splunk SOAR

Bulk container or mission delete

RMcCurdyDOTcom
Explorer

Don't know another way to do it ...  I had created containers from the Splunk export app for SOAR ( don't us that for Mission Control (MC) it got stuck in some kind of loop or something...


so gross but whatever 

 

 

 

export token='YOURAUTOMATIONTOKEN'

while true
do
curl -s -u ":${token}" 'https://YOURCOMPANY.soar.splunkcloud.com/rest/container?search_fields=id&_filter_artifact_count__lte=0&page_size=2200' | python3 -m json.tool | grep -E "(\bid\b)" | sed 's/.*: //g' | tr -d '\n' | sed -re 's/^/{\"ids\":\[/g' -re 's/,$/]}/g' > ids.txt
curl -s -X DELETE -u ":${token}" 'https://YOURCOMPANY.soar.splunkcloud.com/rest/container' -d "`cat ids.txt`"
done

 

 

 

 

Labels (2)
0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...