Building for the Splunk Platform

REST API Access

ChintanaM
Explorer

Dear all,

I am trying to initiate a search using Splunk cloud rest API. Using following code

 

 

 

const accessToken = "--my-super-secret-token--";
const url = "https://company-installation.splunkcloud.com:8089/services/search/jobs";

try {
  const authHeaderValue = `Splunk ${accessToken}`;

  const config = {
    headers: {
      'Authorization': authHeaderValue
    },
    params: {
      'output_mode': 'json',
      'search':'search *'
    }
  };

  const res = await axios.post(url, config);

  return {
    statusCode: 200,
    body: JSON.stringify(res.data),
  };
  
} catch (e) {


  return {
    statusCode: 400,
    body: JSON.stringify(e),
  };
}

 

 

 

 

When the code is executed I get a 401 at line const res = await axios.post(url, config);

My api token is valid and my IP address is whitelisted

When axios.post is replaced with axios.get, I get list of searches back which also verifies token and IP address are good

Could anyone spot why the code is failing to create a search with HTTP POST please?

I am very new to Splunk REST API and any help is much appreciated

 

 

 

Labels (1)
0 Karma
1 Solution

ChintanaM
Explorer

Hi all,

The issue was on how axios was dealing with its payload. Just needed to encode data for to be able to calculate content-length.

Cheers

CM

View solution in original post

0 Karma

ChintanaM
Explorer

Hi all,

The issue was on how axios was dealing with its payload. Just needed to encode data for to be able to calculate content-length.

Cheers

CM

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...