Splunk SOAR

How to import containers via rest api?

dennyw
Engager

We have a need to migrate our phantom data to another instance including the containers. 

Though it's not listed in REST Containers - Splunk Documentation, i was able to export the containers via /rest/container/{id}/export

however, i didn't find the rest endpoint for importing the containers.

any advice will be appreciated.

Labels (1)
0 Karma
1 Solution

phanTom
SplunkTrust
SplunkTrust

@dennyw I think you would be better backing up and restoring to the other system *(must be the same version). The REST call you did pulls down individual files containing the container JSON.

I am not aware of a way to import the .gz files via REST with the only way being the manual press of the Import button.

You may even be better off using a script to hit REST to GET from the old and POST to the new system. You would likely need to remove container id's and source_data_identifiers before POSTing.

As you can see there are a few ways to do things in SOAR!

-- If this helped, please mark as a solution! Happy SOARing --

View solution in original post

0 Karma

phanTom
SplunkTrust
SplunkTrust

@dennyw I think you would be better backing up and restoring to the other system *(must be the same version). The REST call you did pulls down individual files containing the container JSON.

I am not aware of a way to import the .gz files via REST with the only way being the manual press of the Import button.

You may even be better off using a script to hit REST to GET from the old and POST to the new system. You would likely need to remove container id's and source_data_identifiers before POSTing.

As you can see there are a few ways to do things in SOAR!

-- If this helped, please mark as a solution! Happy SOARing --

0 Karma
Get Updates on the Splunk Community!

Announcing the Expansion of the Splunk Academic Alliance Program

The Splunk Community is more than just an online forum — it’s a network of passionate users, administrators, ...

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...