Splunk SOAR

Is any Rest API or link for answer certain prompt ?

johnlee2327
Explorer

All I learning for prompt is that I need to open broser and prompt with SOAR GUI.
Is any Rest API or link available for answer prompt ?
I want to pass some variable in the mail.
If somebody click certain link, It will accept or reject the prompt for event "4" base on API automatically.
It will reduce IT's workload!

Labels (1)
0 Karma

johnlee2327
Explorer

Update.
I have found I can use this API to approve. But still need username password or token T^T.

curl -X POST -k -u "username:password" https://10.250.74.118:8443//rest/approval/15/responses -d "{\"responses\": [\"deny\"]}"


But it showing the error that:

{"failed": true, "message": "Invalid resolution. must be one of approve, deny, delegate"}


Anyone know why?

 

0 Karma

phanTom
SplunkTrust
SplunkTrust

@johnlee2327 

Firstly I would not recommend you use this in email as you will need to embed the username & password in to the link you give. 

External prompts are coming in the next release AFAIK so you may not want to expend a lot of energy on this to then have it natively available. 

For your question I thin you just need to put "deny" as a string not a list object. 

 

-- Hope this helps. Happy SOARing --

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...