its working. thanks import json import requests from requests.auth import HTTPBasicAuth # Disable insecure request warnings if you use self-signed certificates from requests.packages.urllib3.exceptions import InsecureRequestWarning requests.packages.urllib3.disable_warnings(InsecureRequestWarning) # 1. Correct Endpoint Path Mapping # Splunk converts the 'post_xxx' python method into a POST route at '/data/lookup_edit/xxx' url = "https://localhost:8089/servicesNS/nobody/lookup_editor/data/lookup_edit/lookup_contents" lookup_matrix = [ ["id", "name"], # Header row ["104", "abc"], ["105", "xyz"] ] # 2. Re-structured to match the exact method signature variables of post_lookup_contents payload = { "lookup_file": "test.csv", "contents": json.dumps(lookup_matrix), # Must be a serialized JSON string array "namespace": "lookup_editor", # Destination app context (use 'search' or 'lookup_editor') "owner": "nobody", # Mapped to global/nobody context "backup": "false", # Explicit string boolean flag required by controller "isNew": "false" # Explicit flag required to prevent 'already exists' or missing path issues } resp = requests.post( url, data=payload, # Must be sent as form data (x-www-form-urlencoded), NOT raw JSON payload auth=HTTPBasicAuth("admin", "Test@12345"), verify=False ) print("Status Code:", resp.status_code) print("Response:", resp.text)
... View more