Splunk Search

Unable to search using REST API

vinitchaudhari1
New Member

Hi I have a cloud instance version 7.0.2.1 https://prd-p-df4vmzb62ds7.cloud.splunk.com. I am trying to use REST API to run search but I am always getting Page Not Found error. I gave correct username/password. I tried running simple POST call using endpoint utr https://prd-p-df4vmzb62ds7.cloud.splunk.com/services/auth/login but it is not working. If anyone has used REST API then can you please help? I also have local version 5.x but it is not enterprise. Is REST API supported only in enterprise version?

Tags (1)
0 Karma

seegeekrun
Path Finder
0 Karma

seegeekrun
Path Finder

Are you using port 8089?
https://your-instance.com:8089/services/admin...

The UI runs on port 8000 and is typically forwarded from 443. But the API Endpoints are over 8089, which is also the management port.

0 Karma

vinitchaudhari1
New Member

Thanks Seegeekrun for the response. I am using 8089. I just found out that it works with curl but not with Postman or SOAP UI. Is there a way to use Postman or SOAP UI for Splunk REST API?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...