I have Splunk Cloud and an account to connect to my Splunk Cloud. The only thing I want is to not install the service locally and run auth to perform one search. I want to connect to my Splunk Cloud with service of Splunk and get authenticated to get one search.
Is it possible?
Do I have to install Splunk Enterprise locally, even if I have an account in Splunk Cloud?
If you are a current Splunk Cloud customer, you need to file a support case to open port 8089, because it is disabled by default on all Splunk Cloud deployments.
Once you have done that, you should be able to invoke searches via the REST interface from your on-prem applications.
Splunk can restrict REST API access to a list of IP addresses, but if you don't ask for that, the port will be accessible to anyone who has the URL (still need a valid username/password)
Thank you for your answer,
Before I will ask them to activate the api I would Like to know what are the possibilities that I have,
so I will appreciate if you can check it for me :
I am not sure I understand exactly what you are asking. If you have a Splunk Cloud account, you normally never have to install anything locally, but instead connect to your Splunk Cloud instance using your browser.
Can you please try to rephrase your question to make it clearer what you are trying to do?
Thanks I wanted to be sure,because my api rest service from production NOT AVAILABLE
Do you know if this link is the full link to Api REST Service
xxx-my company host
And I Have 2 another questions:
1. It seems that I can not load splunk in iframe because of same -origin problem ,what is the solution for that ?
2. Is there is an option in api rest to get embed url on schedule report in order to load this in iframe, and not the data itself in json or xml format