Splunk SOAR

Is there a way to get all Custom Lists with phantom api?

GeorgeOrwell
Explorer

I'm looking for a way to collect all custom lists.  While I can do so individually for every Custom List with `phantom.get_list()` I still need to have their names to make use of this function. So, is there a way to get all Custom Lists names, or Custom Lists' contents? 
As a workaround I tried making request to "/rest/decided_list", but it doesn't return everything that is accessible through phantom itself. 

0 Karma
1 Solution

phanTom
SplunkTrust
SplunkTrust

@GeorgeOrwell are you adding any page_size argument to the REST call??

decided_list is the right endpoint for ALL lists on the platform but REST calls usually have a page limit.

Try:

/rest/decided_list?page_size=0

 

Here is the docs for all the query items you can use for REST:
https://docs.splunk.com/Documentation/SOARonprem/5.3.2/PlatformAPI/RESTQueryData 

View solution in original post

Tags (1)

phanTom
SplunkTrust
SplunkTrust

@GeorgeOrwell are you adding any page_size argument to the REST call??

decided_list is the right endpoint for ALL lists on the platform but REST calls usually have a page limit.

Try:

/rest/decided_list?page_size=0

 

Here is the docs for all the query items you can use for REST:
https://docs.splunk.com/Documentation/SOARonprem/5.3.2/PlatformAPI/RESTQueryData 

Tags (1)
Get Updates on the Splunk Community!

Fall Into Learning with New Splunk Education Courses

Every month, Splunk Education releases new courses to help you branch out, strengthen your data science roots, ...

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...