# Splunk SOAR REST API

**Canonical:** https://apis.io/apis/splunk-soar/splunk-soar-rest-api/  
**Provider:** Splunk SOAR — https://apis.io/providers/splunk-soar/  
**Base URL:** https://{soar-host}/rest  
**Documentation:** https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference

Splunk SOAR REST API is published by [Splunk SOAR](https://apis.io/providers/splunk-soar/) on the [APIs.io](https://apis.io/) network. Tagged areas include Security, Automation, Orchestration, Incident Response, and REST. The published artifact set on APIs.io includes API documentation, an API reference, a getting-started guide, authentication docs, and rate-limit docs.

The Splunk SOAR REST API creates, updates, queries and selectively removes the objects the platform automates against — containers, artifacts, playbooks, action runs, apps, assets, CEF fields, indicators, evidence, notes, vault files, workbooks, custom lists, custom functions, roles, users, severities, aggregation rules, approvals, multi-tenancy and system settings. Requests must be made over HTTPS against the customer's own SOAR tenant.

## Machine-readable artifacts (9)

- **Documentation** — https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference
- **APIReference** — https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference
- **GettingStarted** — https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference/using-the-splunk-soar-rest-api/using-the-rest-api-reference-for-splunk-soar-cloud
- **Authentication** — https://raw.githubusercontent.com/api-evangelist/splunk-soar/refs/heads/main/authentication/splunk-soar-authentication.yml
- **Conventions** — https://raw.githubusercontent.com/api-evangelist/splunk-soar/refs/heads/main/conventions/splunk-soar-conventions.yml
- **ErrorCatalog** — https://raw.githubusercontent.com/api-evangelist/splunk-soar/refs/heads/main/errors/splunk-soar-problem-types.yml
- **DataModel** — https://raw.githubusercontent.com/api-evangelist/splunk-soar/refs/heads/main/data-model/splunk-soar-data-model.yml
- **RateLimits** — https://raw.githubusercontent.com/api-evangelist/splunk-soar/refs/heads/main/rate-limits/splunk-soar-rate-limits.yml
- **APIsJSON** — https://raw.githubusercontent.com/api-evangelist/splunk-soar/refs/heads/main/apis.yml

## Tags

Security, Automation, Orchestration, Incident Response, REST

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/splunk-soar/splunk-soar-rest-api/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/splunk-soar/.
