Splunk SOAR

Is there a way to get all Custom Lists with phantom api?

GeorgeOrwell
Explorer

I'm looking for a way to collect all custom lists.  While I can do so individually for every Custom List with `phantom.get_list()` I still need to have their names to make use of this function. So, is there a way to get all Custom Lists names, or Custom Lists' contents? 
As a workaround I tried making request to "/rest/decided_list", but it doesn't return everything that is accessible through phantom itself. 

0 Karma
1 Solution

phanTom
SplunkTrust
SplunkTrust

@GeorgeOrwell are you adding any page_size argument to the REST call??

decided_list is the right endpoint for ALL lists on the platform but REST calls usually have a page limit.

Try:

/rest/decided_list?page_size=0

 

Here is the docs for all the query items you can use for REST:
https://docs.splunk.com/Documentation/SOARonprem/5.3.2/PlatformAPI/RESTQueryData 

View solution in original post

Tags (1)

phanTom
SplunkTrust
SplunkTrust

@GeorgeOrwell are you adding any page_size argument to the REST call??

decided_list is the right endpoint for ALL lists on the platform but REST calls usually have a page limit.

Try:

/rest/decided_list?page_size=0

 

Here is the docs for all the query items you can use for REST:
https://docs.splunk.com/Documentation/SOARonprem/5.3.2/PlatformAPI/RESTQueryData 

Tags (1)
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...