Splunk Search

How to upload a lookup file to a Splunk Cloud "staging area" or through REST API?

jfgomez0912
Explorer

Hi,

In order to automate the deployment pipeline of Splunk Apps into different instances, our team has the requirement of uploading the lookups in our development environment (Splunk enterprise on-premise) to our production environment (Splunk Cloud) automatically.

After reading the Splunk REST API documentation, we encountered a way to move any file from a staging area to the lookups stored in the apps as follows:

https://host:mPort/services/data/lookup-table-files/{name}
POST
Modify a lookup table file by replacing it with a file from the upload staging area.

In order to get this type of automation, is there any way to upload a file to a Splunk Cloud "staging area", or is there any possibility to upload lookup via REST API to Splunk Cloud?

Thanks.

Labels (1)

danan5
Path Finder

Hi,

Did you ever find a way to programmatically upload to the staging area?

Regards,

0 Karma

chartastic
Explorer

Last I heard from support on the subject, this was not currently possible. Though this was July 2020 or so.

Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...