We're heavy SplunkCloud users and have run into a roadblock. We have a lookup CSV file that needs to be updated daily - slowly changing customer information - but try as I might, I cannot find an automated way to upload these CSVs without using the Web user interface.
The closest thing I can find is
https://<host>:<mPort>/services/data/lookup-table-files/{name}
where the POST method will allow you to "Modify a lookup table file by replacing it with a file from
the upload staging area."
But in SplunkCloud, we don't have access to the upload staging area - we don't have file access at all, as far as I can tell.
How can this be done? I'd like to do this using something simple like curl:
curl -k -u admin:password --form upload=@/home/me/lookup.csv https://mycompany.splunkcloud.com:8089/rest-api-call-to-upload-and-update-existing-csv-lookup
... View more