Splunk SOAR

Is any Rest API or link for answer certain prompt ?

johnlee2327
Explorer

All I learning for prompt is that I need to open broser and prompt with SOAR GUI.
Is any Rest API or link available for answer prompt ?
I want to pass some variable in the mail.
If somebody click certain link, It will accept or reject the prompt for event "4" base on API automatically.
It will reduce IT's workload!

Labels (1)
0 Karma

johnlee2327
Explorer

Update.
I have found I can use this API to approve. But still need username password or token T^T.

curl -X POST -k -u "username:password" https://10.250.74.118:8443//rest/approval/15/responses -d "{\"responses\": [\"deny\"]}"


But it showing the error that:

{"failed": true, "message": "Invalid resolution. must be one of approve, deny, delegate"}


Anyone know why?

 

0 Karma

phanTom
SplunkTrust
SplunkTrust

@johnlee2327 

Firstly I would not recommend you use this in email as you will need to embed the username & password in to the link you give. 

External prompts are coming in the next release AFAIK so you may not want to expend a lot of energy on this to then have it natively available. 

For your question I thin you just need to put "deny" as a string not a list object. 

 

-- Hope this helps. Happy SOARing --

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...