Splunk SOAR

Is any Rest API or link for answer certain prompt ?

johnlee2327
Explorer

All I learning for prompt is that I need to open broser and prompt with SOAR GUI.
Is any Rest API or link available for answer prompt ?
I want to pass some variable in the mail.
If somebody click certain link, It will accept or reject the prompt for event "4" base on API automatically.
It will reduce IT's workload!

Labels (1)
0 Karma

johnlee2327
Explorer

Update.
I have found I can use this API to approve. But still need username password or token T^T.

curl -X POST -k -u "username:password" https://10.250.74.118:8443//rest/approval/15/responses -d "{\"responses\": [\"deny\"]}"


But it showing the error that:

{"failed": true, "message": "Invalid resolution. must be one of approve, deny, delegate"}


Anyone know why?

 

0 Karma

phanTom
SplunkTrust
SplunkTrust

@johnlee2327 

Firstly I would not recommend you use this in email as you will need to embed the username & password in to the link you give. 

External prompts are coming in the next release AFAIK so you may not want to expend a lot of energy on this to then have it natively available. 

For your question I thin you just need to put "deny" as a string not a list object. 

 

-- Hope this helps. Happy SOARing --

-- Hope this helps, if so consider leaving some Karma. Even better is if this fixed your issue, that you mark as a solution for others to find. Happy SOARing!! ---
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...