Thanks @richgalloway I'm trying the Splunk App Inspect API approach now, but ran into the following issue after trying to authenticate. I'm using my Splunk username and password , so I'm confused as to why I'm unable to connect to the URL. $ curl -X GET \ > -u john.smith \ --url "https://api.splunk.com/2.0/rest/login/splunk" Enter host password for user 'john.smith': curl: (3) Host name ' --url' contains bad letter {"status_code":401,"status":"error","msg":"Failed to authenticate user","errors":"401 - {\"status\":3, \"message\":[{\"major\":1,\"type\":\"User Error\",\"title\":\"UNAUTHORIZED\",\"short\":\"Could not authenticate user john.smith\",\"long\":\"\",\"hint\":\"\",\"stack\":\"\",\"product\":\"App - Core\",\"
... View more