Splunk SOAR

Is any Rest API or link for answer certain prompt ?

johnlee2327
Explorer

All I learning for prompt is that I need to open broser and prompt with SOAR GUI.
Is any Rest API or link available for answer prompt ?
I want to pass some variable in the mail.
If somebody click certain link, It will accept or reject the prompt for event "4" base on API automatically.
It will reduce IT's workload!

Labels (1)
0 Karma

johnlee2327
Explorer

Update.
I have found I can use this API to approve. But still need username password or token T^T.

curl -X POST -k -u "username:password" https://10.250.74.118:8443//rest/approval/15/responses -d "{\"responses\": [\"deny\"]}"


But it showing the error that:

{"failed": true, "message": "Invalid resolution. must be one of approve, deny, delegate"}


Anyone know why?

 

0 Karma

phanTom
SplunkTrust
SplunkTrust

@johnlee2327 

Firstly I would not recommend you use this in email as you will need to embed the username & password in to the link you give. 

External prompts are coming in the next release AFAIK so you may not want to expend a lot of energy on this to then have it natively available. 

For your question I thin you just need to put "deny" as a string not a list object. 

 

-- Hope this helps. Happy SOARing --

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...