Splunk SOAR

How to upload/attach a file (vault) to a container via rest api?

rudnima7
New Member

I am looking for a rest endpoint to be able to attach the source file to the event. You can do this through the browser, and through the rest api I found an endpoint that only allows you to download the metadata of a given file. Is it possible to upload a source file via rest api?

https://docs.splunk.com/Documentation/SOAR/current/PlatformAPI/RESTVault - only GET methods for metadata, like hash, filename etc.

 

Labels (1)
0 Karma

kblaine
Explorer

I am not sure about using the rest endpoint to do it but there is a direct phantom api that allow you to add to the event called phantom.vault_add

0 Karma
Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

[Puzzles] Solve, Learn, Repeat: Nested loops in Event Conversion

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...