Splunk SOAR REST API
The Splunk SOAR REST API creates, updates, queries and selectively removes the objects the platform automates against — containers, artifacts, playbooks, action runs, apps, assets, CEF fields, indicators, evidence, notes, vault files, workbooks, custom lists, custom functions, roles, users, severities, aggregation rules, approvals, multi-tenancy and system settings. Requests must be made over HTTPS against the customer's own SOAR tenant.