Splunk SOAR REST API
The Splunk SOAR REST API creates, updates, queries and selectively removes the objects the platform automates against — containers, artifacts, playbooks, action runs, apps, assets, CEF fields, indicators, evidence, notes, vault files, workbooks, custom lists, custom functions, roles, users, severities, aggregation rules, approvals, multi-tenancy and system settings. Requests must be made over HTTPS against the customer's own SOAR tenant.
Documentation
Documentation
https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference
APIReference
https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference
GettingStarted
https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference/using-the-splunk-soar-rest-api/using-the-rest-api-reference-for-splunk-soar-cloud
Authentication
https://raw.githubusercontent.com/api-evangelist/splunk-soar/refs/heads/main/authentication/splunk-soar-authentication.yml
RateLimits
https://raw.githubusercontent.com/api-evangelist/splunk-soar/refs/heads/main/rate-limits/splunk-soar-rate-limits.yml
Other Resources
Conventions
https://raw.githubusercontent.com/api-evangelist/splunk-soar/refs/heads/main/conventions/splunk-soar-conventions.yml
ErrorCatalog
https://raw.githubusercontent.com/api-evangelist/splunk-soar/refs/heads/main/errors/splunk-soar-problem-types.yml
DataModel
https://raw.githubusercontent.com/api-evangelist/splunk-soar/refs/heads/main/data-model/splunk-soar-data-model.yml
APIsJSON
https://raw.githubusercontent.com/api-evangelist/splunk-soar/refs/heads/main/apis.yml