Splunk website screenshot

Splunk

Splunk is a platform for searching, monitoring, and analyzing machine-generated big data via a web-style interface.

Splunk publishes 3 APIs on the APIs.io network: Data Inputs API, Index API, and Search API. Tagged areas include Analytics, Data Analysis, Logging, Machine Data, and Monitoring.

The Splunk catalog on APIs.io includes 2 JSON-LD contexts and 2 Spectral governance rulesets.

Splunk’s developer surface includes authentication, engineering blog, support, documentation, getting-started guide, pricing, signup flow, and 40 more developer resources.

71.1/100 exemplar ▬ flat Agent 48/100 agent ready Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFreeSelf serve⚡ Free to try
14 APIs 1 MCP Servers 8 Features 6 Use Cases
AnalyticsData AnalysisLoggingMachine DataMonitoringObservabilityPlatformSecuritySIEM

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 71.1/100 · exemplar
Contract Quality 19.1 / 25
Developer Ergonomics 14.8 / 20
Commercial Clarity 15.8 / 20
Operational Transparency 8.9 / 13
Governance 7.0 / 12
Discoverability 5.6 / 10
Agent readiness — 48/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 12 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 7 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/splunk: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 14

Individual APIs this provider publishes, each with its own machine-readable definition.

Splunk

API monitoring checks to see if API-connected resources are available, working properly and responding to calls.

Splunk Cloud Platform REST API

The Splunk Cloud Platform REST API provides a subset of the Splunk Enterprise REST API endpoints for managing and interacting with your Splunk Cloud Platform deployment. Access ...

Splunk Cloud Admin Config Service (ACS) API

The Admin Config Service (ACS) is a cloud-native API that provides programmatic self-service administration capabilities for Splunk Cloud Platform. Administrators can use the AC...

Splunk Observability Cloud API

The Splunk Observability Cloud API provides REST endpoints for sending and managing metrics, traces, and events. It supports infrastructure monitoring, application performance m...

Splunk SOAR REST API

The Splunk SOAR REST API enables programmatic creation, updating, and management of security automation objects including containers, assets, playbooks, indicators, lists, and a...

Splunk Enterprise Security API

The Splunk Enterprise Security API provides REST endpoints for accessing and modifying findings, investigations, risk scores, assets, and identities in Splunk Enterprise Securit...

Splunk IT Service Intelligence (ITSI) REST API

The Splunk IT Service Intelligence (ITSI) REST API allows bulk creation and updating of ITOA interface objects such as entities, services, and KPI base searches. ITSI is a monit...

Splunk HTTP Event Collector (HEC) API

The Splunk HTTP Event Collector (HEC) is a high-performance REST API data input that accepts JSON or raw text data sent over HTTP or HTTPS. It uses token-based authentication an...

Splunk Intelligence Management API

The Splunk Intelligence Management (formerly ThreatStream) API provides REST v2.0 endpoints for managing threat intelligence data including indicators, observables, and intellig...

Splunk SOAR Playbook Automation API

The Splunk SOAR Playbook Automation API provides Python APIs for developing playbooks and automation within Splunk SOAR. It includes container, playbook, data access, vault, net...

Splunk AppInspect API

The Splunk AppInspect API validates Splunk apps and add-ons against Splunk best practices and requirements for publishing to Splunkbase or installing on Splunk Cloud Platform. I...

Splunk Data Inputs API

Endpoints for configuring and managing data inputs including monitors, TCP/UDP inputs, scripted inputs, and HTTP Event Collector (HEC) tokens. Data inputs define how Splunk inge...

Splunk Index API

Endpoints for managing Splunk indexes, which store and organize ingested data. Indexes can be created, modified, listed, and configured for retention and storage policies.

Splunk Search API

Endpoints for creating, managing, and retrieving search jobs and their results. Splunk search processing language (SPL) queries are submitted as search jobs that run asynchronou...

Scroll for all 14

Postman Collections 1

Ready-to-run Postman collections for exercising this provider's APIs.

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Arazzo Workflows 6

Multi-step API workflows described with the Arazzo specification.

Splunk Finalize, Read, and Clean Up a Search Job

Dispatch a long search, finalize it early, read partial results, then delete the job.

ARAZZO

Splunk HEC Ingest an Event and Confirm Indexing

Provision a HEC token with acknowledgment, send a JSON event, and confirm it was indexed.

ARAZZO

Splunk Provision an Index and Attach a Monitor Input

Create an event index, verify it, then create a file monitor input that feeds it.

ARAZZO

Splunk Ingest Raw Data then Search for It

Send raw text to HEC, then run an SPL search and poll it to confirm the data landed.

ARAZZO

Splunk Run a Search Job and Retrieve Results

Dispatch an SPL search, poll the job until it finishes, then read the results.

ARAZZO

Splunk Search and Retrieve Raw Events

Run an SPL search, wait for it to finish, then pull the untransformed events.

ARAZZO

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

MCP Server

MCP SERVER

GraphQL 1

GraphQL schemas published by this provider.

Splunk GraphQL Schema

Conceptual GraphQL schema for the Splunk platform, covering search, indexing, data inputs, access control, dashboards, saved searches, metrics, clustering, licensing, and diagno...

GRAPHQL

Pricing Plans 1

Published pricing tiers and plan structures.

Splunk Plans Pricing

3 plans

PLANS

Rate Limits 1

Documented rate limits and quota policies.

Splunk Rate Limits

2 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Features 8

Notable capabilities this provider offers.

Splunk (now Cisco): hundreds of services across Observability + SIEM
Detailed pricing: see https://www.splunk.com/en_us/products/pricing.html
Service: Splunk Enterprise / Cloud (data ingest)
Service: Splunk Observability Cloud (APM, Logs, RUM, Synthetics)
Service: Splunk SOAR
Service: Splunk Enterprise Security (SIEM)
Service: Splunk ITSI
Service: Splunk SOC Platform

Scroll for all 8

Semantic Vocabularies 2

JSON-LD contexts and semantic vocabularies used across these APIs.

Splunk Context

0 classes · 15 properties

JSON-LD

Splunk Enterprise Rest Context

0 classes · 0 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

Splunk API Rules

5 rules · 3 warnings 2 info

SPECTRAL

Splunk API Rules

16 rules · 8 errors 7 warnings 1 info

SPECTRAL

JSON Schema 48

Standalone JSON Schema definitions for this provider's data models.

ErrorResponse

1 properties

JSON SCHEMA

HecEvent

7 properties

JSON SCHEMA

HecResponse

4 properties

JSON SCHEMA

HecTokenCreateRequest

8 properties

JSON SCHEMA

HecTokenList

3 properties

JSON SCHEMA

HecToken

2 properties

JSON SCHEMA

IndexCreateRequest

10 properties

JSON SCHEMA

IndexList

3 properties

JSON SCHEMA

Index

2 properties

JSON SCHEMA

IndexUpdateRequest

7 properties

JSON SCHEMA

MonitorInputCreateRequest

10 properties

JSON SCHEMA

MonitorInputList

3 properties

JSON SCHEMA

MonitorInput

2 properties

JSON SCHEMA

MonitorInputUpdateRequest

5 properties

JSON SCHEMA

Paging

3 properties

JSON SCHEMA

SearchJobCreateRequest

19 properties

JSON SCHEMA

SearchJobList

4 properties

JSON SCHEMA

SearchJob

2 properties

JSON SCHEMA

SearchResults

6 properties

JSON SCHEMA

TcpInputList

3 properties

JSON SCHEMA

TcpInput

2 properties

JSON SCHEMA

UdpInputList

3 properties

JSON SCHEMA

UdpInput

2 properties

JSON SCHEMA

ErrorResponse

1 properties

JSON SCHEMA

Splunk Event

19 properties

JSON SCHEMA

HecEvent

7 properties

JSON SCHEMA

HecResponse

4 properties

JSON SCHEMA

HecToken

2 properties

JSON SCHEMA

HecTokenCreateRequest

8 properties

JSON SCHEMA

HecTokenList

4 properties

JSON SCHEMA

Index

2 properties

JSON SCHEMA

IndexCreateRequest

10 properties

JSON SCHEMA

IndexList

4 properties

JSON SCHEMA

IndexUpdateRequest

7 properties

JSON SCHEMA

MonitorInput

2 properties

JSON SCHEMA

MonitorInputCreateRequest

10 properties

JSON SCHEMA

MonitorInputList

4 properties

JSON SCHEMA

MonitorInputUpdateRequest

5 properties

JSON SCHEMA

Paging

3 properties

JSON SCHEMA

Splunk Search Job

9 properties

JSON SCHEMA

SearchJob

2 properties

JSON SCHEMA

SearchJobCreateRequest

19 properties

JSON SCHEMA

SearchJobList

5 properties

JSON SCHEMA

SearchResults

6 properties

JSON SCHEMA

TcpInput

2 properties

JSON SCHEMA

TcpInputList

4 properties

JSON SCHEMA

UdpInput

2 properties

JSON SCHEMA

UdpInputList

4 properties

JSON SCHEMA

Scroll for all 48

JSON Structure 24

JSON Structure definitions describing this provider's data shapes.

Splunk Enterprise Rest Hec Event Structure

7 properties

JSON STRUCTURE

Splunk Enterprise Rest Hec Token Structure

2 properties

JSON STRUCTURE

Splunk Enterprise Rest Index Structure

2 properties

JSON STRUCTURE

Splunk Enterprise Rest Paging Structure

3 properties

JSON STRUCTURE

Splunk Enterprise Rest Tcp Input Structure

2 properties

JSON STRUCTURE

Splunk Enterprise Rest Udp Input Structure

2 properties

JSON STRUCTURE

Splunk Structure

0 properties

JSON STRUCTURE

Scroll for all 24

Examples 46

Example request and response payloads for these APIs.

Splunk Getindex Example

6 fields

EXAMPLE

Splunk Sendevent Example

6 fields

EXAMPLE

Scroll for all 46

Security Posture 4

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Splunk Authentication

apiKey/http · 3 schemes

SECURITY

Splunk Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Splunk Vulnerability Disclosure

security.txt · contact published

SECURITY

Splunk Trust Center

SOC 2, ISO 27001, ISO 27017, ISO 27018, PCI DSS, HIPAA, FedRAMP, GDPR, CSA STAR

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Splunk Agentic Access

26 operations · 13 acting · 1 human-in-the-loop

26 operations · 13 acting

AGENTIC

Use Cases 6

What developers build with this provider.

Security Information and Event Management

Centralize security event data for real-time threat detection, investigation, and compliance reporting.

IT Operations Monitoring

Monitor infrastructure health, application performance, and service availability across hybrid environments.

Log Management

Collect, index, and analyze log data from servers, applications, and network devices for troubleshooting.

Incident Response Automation

Automate security incident triage, enrichment, and response using SOAR playbooks and integrations.

Application Performance Monitoring

Trace application requests end-to-end to identify bottlenecks and optimize performance.

Compliance and Audit

Generate compliance reports and audit trails from indexed data to meet regulatory requirements.

Integrations 8

Pre-built integrations with other platforms and tools.

AWS

Ingest and analyze AWS CloudTrail, CloudWatch, VPC Flow Logs, and other AWS service data.

Azure

Collect and analyze Azure activity logs, metrics, and diagnostic data.

Google Cloud

Ingest Google Cloud audit logs, metrics, and Pub/Sub messages for cloud monitoring.

Kubernetes

Monitor Kubernetes clusters with metrics, logs, and events from containers and orchestration.

ServiceNow

Integrate Splunk alerts and incidents with ServiceNow ITSM for ticketing and workflow automation.

PagerDuty

Trigger PagerDuty incidents from Splunk alerts for on-call notification and escalation.

Cisco

Collect and analyze Cisco network device logs, firewall events, and security telemetry.

CrowdStrike

Ingest CrowdStrike Falcon endpoint detection data for correlated threat analysis.

Scroll for all 8

Resources

Get Started 4

Portal, sign-up, and the first successful call

Documentation 6

Reference material describing how the API behaves

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 7

Pagination, idempotency, versioning, errors, and events

Scroll for all 7

Build 8

SDKs, sample code, and the tooling you integrate with

Scroll for all 8

Access & Security 7

Authentication, authorization, and security posture

Scroll for all 7

Operate 5

Status, limits, changes, and where to get help

Commercial 4

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Other 2

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: splunk
name: Splunk
description: Splunk is a platform for searching, monitoring, and analyzing machine-generated big data via a web-style interface.
accessModel:
  pricing: free
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Free · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://www.splunk.com/content/dam/splunk2/images/icons/favicons/favicon.ico
url: https://raw.githubusercontent.com/api-evangelist/splunk/refs/heads/main/apis.yml
created: '2025-01-08'
modified: '2026-05-19'
specificationVersion: '0.19'
type: Index
access: 3rd-Party
position: Consumer
tags:
- Analytics
- Data Analysis
- Logging
- Machine Data
- Monitoring
- Observability
- Platform
- Security
- SIEM
apis:
- aid: splunk:splunk
  name: Splunk
  description: API monitoring checks to see if API-connected resources are available, working properly and responding to calls.
  humanURL: https://www.splunk.com/en_us/blog/learn/api-monitoring.html
  tags: []
  properties:
  - type: Documentation
    url: https://www.splunk.com/en_us/blog/learn/api-monitoring.html
  - url: graphql/splunk-graphql.md
    type: GraphQL
- aid: splunk:splunk-cloud-platform-rest-api
  name: Splunk Cloud Platform REST API
  description: The Splunk Cloud Platform REST API provides a subset of the Splunk Enterprise REST API endpoints for managing
    and interacting with your Splunk Cloud Platform deployment. Access requires port 8089 to be opened by Splunk Support.
  humanURL: https://help.splunk.com/en/splunk-cloud-platform/rest-api-reference
  tags:
  - Cloud
  - Data
  - Management
  - REST
  - Search
  properties:
  - type: Documentation
    url: https://help.splunk.com/en/splunk-cloud-platform/rest-api-reference
  - type: GettingStarted
    url: https://docs.splunk.com/Documentation/SplunkCloud/latest/RESTTUT/RESTandCloud
  - type: APIReference
    url: https://docs.splunk.com/Documentation/SplunkCloud/latest/RESTREF/RESTprolog
- aid: splunk:splunk-cloud-admin-config-service-api
  name: Splunk Cloud Admin Config Service (ACS) API
  description: The Admin Config Service (ACS) is a cloud-native API that provides programmatic self-service administration
    capabilities for Splunk Cloud Platform. Administrators can use the ACS API to manage indexes, IP allow lists, HEC tokens,
    users, and roles without assistance from Splunk Support. ACS provides an OpenAPI 3.0 specification.
  humanURL: https://docs.splunk.com/Documentation/SplunkCloud/latest/Config/ACSIntro
  tags:
  - Administration
  - Cloud
  - Configuration
  - Management
  properties:
  - type: Documentation
    url: https://docs.splunk.com/Documentation/SplunkCloud/latest/Config/ACSIntro
  - type: GettingStarted
    url: https://docs.splunk.com/Documentation/SplunkCloud/latest/Config/ACSusage
  - type: APIReference
    url: https://docs.splunk.com/Documentation/SplunkCloud/latest/Config/ACSREF
- aid: splunk:splunk-observability-cloud-api
  name: Splunk Observability Cloud API
  description: The Splunk Observability Cloud API provides REST endpoints for sending and managing metrics, traces, and events.
    It supports infrastructure monitoring, application performance monitoring (APM), real user monitoring, and synthetic monitoring
    use cases.
  humanURL: https://dev.splunk.com/observability/
  tags:
  - APM
  - Metrics
  - Monitoring
  - Observability
  - Traces
  properties:
  - type: Documentation
    url: https://dev.splunk.com/observability/docs
  - type: APIReference
    url: https://dev.splunk.com/observability/reference
  - type: APIReference
    url: https://dev.splunk.com/observability/docs/apibasics/api_list/
    title: API List
  - type: Authentication
    url: https://dev.splunk.com/observability/docs/apibasics/authentication_basics/
  - type: Documentation
    url: https://dev.splunk.com/observability/docs/datamodel/ingest/
    title: Data Ingest
  - type: APIReference
    url: https://dev.splunk.com/observability/reference/api/ingest_data/latest
    title: Ingest Data Reference
  - type: Documentation
    url: https://dev.splunk.com/observability/docs/administration/authtokens
    title: Auth Tokens
- aid: splunk:splunk-soar-rest-api
  name: Splunk SOAR REST API
  description: The Splunk SOAR REST API enables programmatic creation, updating, and management of security automation objects
    including containers, assets, playbooks, indicators, lists, and audit records. REST API requests must be performed over
    HTTPS with token-based or basic authentication.
  humanURL: https://docs.splunk.com/Documentation/SOAR/current/PlatformAPI/Using
  tags:
  - Automation
  - Orchestration
  - Playbooks
  - Security
  - SOAR
  properties:
  - type: Documentation
    url: https://docs.splunk.com/Documentation/SOAR/current/PlatformAPI/Using
  - type: Documentation
    url: https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference/using-the-splunk-soar-rest-api/using-the-rest-api-reference-for-splunk-soar-cloud
    title: SOAR Cloud REST API Reference
  - type: APIReference
    url: https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference/container-endpoints/rest-containers
    title: Container Endpoints
  - type: APIReference
    url: https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference/artifact-endpoints/rest-artifact
    title: Artifact Endpoints
  - type: Documentation
    url: https://help.splunk.com/en/splunk-soar/soar-on-premises/rest-api-reference/7.1.0/using-the-splunk-soar-rest-api/using-the-rest-api-reference-for-splunk-soar-on-premises
    title: SOAR On-Premises REST API Reference
- aid: splunk:splunk-enterprise-security-api
  name: Splunk Enterprise Security API
  description: The Splunk Enterprise Security API provides REST endpoints for accessing and modifying findings, investigations,
    risk scores, assets, and identities in Splunk Enterprise Security. It includes an OpenAPI specification for download.
  humanURL: https://help.splunk.com/en/splunk-enterprise-security-8/api-reference
  tags:
  - Enterprise Security
  - Findings
  - Investigations
  - Security
  - SIEM
  properties:
  - type: Documentation
    url: https://help.splunk.com/en/splunk-enterprise-security-8/api-reference
  - type: APIReference
    url: https://help.splunk.com/en/splunk-enterprise-security-8/rest-api-reference
  - type: GettingStarted
    url: https://dev.splunk.com/enterprise/docs/devtools/enterprisesecurity
  - type: APIReference
    url: https://help.splunk.com/en/splunk-enterprise-security-8/rest-api-reference/8.0/threat-intelligence-endpoints/threat-intelligence-api-reference
    title: Threat Intelligence API
  - type: Documentation
    url: https://dev.splunk.com/enterprise/docs/devtools/enterprisesecurity/threatintelligenceframework/
    title: Threat Intelligence Framework
- aid: splunk:splunk-itsi-rest-api
  name: Splunk IT Service Intelligence (ITSI) REST API
  description: The Splunk IT Service Intelligence (ITSI) REST API allows bulk creation and updating of ITOA interface objects
    such as entities, services, and KPI base searches. ITSI is a monitoring and analytics solution powered by artificial intelligence
    for IT Operations (AIOps).
  humanURL: https://help.splunk.com/en/splunk-it-service-intelligence/splunk-it-service-intelligence/leverage-rest-apis/4.19/itsi-rest-api-schema/itsi-rest-api-schema
  tags:
  - AIOps
  - IT Service Intelligence
  - ITSI
  - Monitoring
  properties:
  - type: Documentation
    url: https://help.splunk.com/en/splunk-it-service-intelligence/splunk-it-service-intelligence/leverage-rest-apis/4.19/itsi-rest-api-schema/itsi-rest-api-schema
  - type: APIReference
    url: https://help.splunk.com/en/splunk-it-service-intelligence/splunk-it-service-intelligence/leverage-rest-apis/4.18/itsi-rest-api-reference/itsi-rest-api-reference
- aid: splunk:splunk-http-event-collector-api
  name: Splunk HTTP Event Collector (HEC) API
  description: The Splunk HTTP Event Collector (HEC) is a high-performance REST API data input that accepts JSON or raw text
    data sent over HTTP or HTTPS. It uses token-based authentication and provides endpoints for sending events (/services/collector/event),
    raw data (/services/collector/raw), and checking indexing status (/services/collector/ack).
  humanURL: https://docs.splunk.com/Documentation/Splunk/latest/Data/UsetheHTTPEventCollector
  tags:
  - Data Ingestion
  - Events
  - HEC
  - Logging
  - REST
  properties:
  - type: Documentation
    url: https://docs.splunk.com/Documentation/Splunk/latest/Data/UsetheHTTPEventCollector
  - type: APIReference
    url: https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/HECRESTendpoints
  - type: Documentation
    url: https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/FormateventsforHTTPEventCollector
    title: Event Format
  - type: Documentation
    url: https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/HECExamples
    title: HEC Examples
  - type: GettingStarted
    url: https://dev.splunk.com/view/event-collector/SP-CAAAE6M
- aid: splunk:splunk-intelligence-management-api
  name: Splunk Intelligence Management API
  description: The Splunk Intelligence Management (formerly ThreatStream) API provides REST v2.0 endpoints for managing threat
    intelligence data including indicators, observables, and intelligence sources. It supports STIX and TAXII formats for
    sharing cyber threat intelligence over HTTPS.
  humanURL: https://docs.splunk.com/Documentation/SIM/current/Develop/RESTv20
  tags:
  - Indicators
  - Security
  - STIX
  - TAXII
  - Threat Intelligence
  properties:
  - type: Documentation
    url: https://docs.splunk.com/Documentation/SIM/current/Develop/RESTv20
  - type: Documentation
    url: https://docs.splunk.com/Documentation/SIM/current/User/Threatintelsources
    title: Threat Intel Sources
  - type: Documentation
    url: https://docs.splunk.com/Documentation/SIM/current/Intro/UsagePolicy
    title: Usage Policy
- aid: splunk:splunk-soar-playbook-automation-api
  name: Splunk SOAR Playbook Automation API
  description: The Splunk SOAR Playbook Automation API provides Python APIs for developing playbooks and automation within
    Splunk SOAR. It includes container, playbook, data access, vault, network, and session automation APIs for building detailed
    security orchestration workflows.
  humanURL: https://help.splunk.com/en/splunk-soar/soar-cloud/develop-apps/python-playbook-api-reference/overview/about-splunk-soar-cloud-playbook-automation-apis
  tags:
  - Automation
  - Orchestration
  - Playbooks
  - Security
  - SOAR
  properties:
  - type: Documentation
    url: https://help.splunk.com/en/splunk-soar/soar-cloud/develop-apps/python-playbook-api-reference/overview/about-splunk-soar-cloud-playbook-automation-apis
  - type: APIReference
    url: https://help.splunk.com/en/splunk-soar/soar-cloud/develop-apps/python-playbook-api-reference/automation-api/container-automation-api
    title: Container Automation
  - type: APIReference
    url: https://help.splunk.com/en/splunk-soar/soar-cloud/develop-apps/python-playbook-api-reference/automation-api/playbook-automation-api
    title: Playbook Automation
  - type: APIReference
    url: https://help.splunk.com/en/splunk-soar/soar-cloud/develop-apps/python-playbook-api-reference/automation-api/data-access-automation-api
    title: Data Access Automation
  - type: APIReference
    url: https://help.splunk.com/en/splunk-soar/soar-cloud/develop-apps/python-playbook-api-reference/automation-api/vault-automation-api
    title: Vault Automation
- aid: splunk:splunk-appinspect-api
  name: Splunk AppInspect API
  description: The Splunk AppInspect API validates Splunk apps and add-ons against Splunk best practices and requirements
    for publishing to Splunkbase or installing on Splunk Cloud Platform. It provides automated app vetting through a REST
    API.
  humanURL: https://dev.splunk.com/enterprise/docs/relnotes/relnotes-appinspectapi/whatsnew
  tags:
  - Apps
  - Cloud
  - Splunkbase
  - Validation
  properties:
  - type: ChangeLog
    url: https://dev.splunk.com/enterprise/docs/relnotes/relnotes-appinspectapi/whatsnew
  - type: APIReference
    url: https://dev.splunk.com/enterprise/reference
- aid: splunk:splunk-data-inputs-api
  name: Splunk Data Inputs API
  description: Endpoints for configuring and managing data inputs including monitors, TCP/UDP inputs, scripted inputs, and
    HTTP Event Collector (HEC) tokens. Data inputs define how Splunk ingests data.
  humanURL: https://www.splunk.com/en_us/blog/learn/api-monitoring.html
  tags:
  - Data Inputs
  properties:
  - type: OpenAPI
    url: openapi/splunk-data-inputs-api-openapi.yml
  - type: Documentation
    url: https://docs.splunk.com/Documentation/Splunk/latest/RESTREF/RESTprolog
  - type: GettingStarted
    url: https://docs.splunk.com/Documentation/Splunk/latest/RESTUM/RESTusing
  - type: APIReference
    url: https://dev.splunk.com/enterprise/reference
  - type: APIReference
    url: https://help.splunk.com/en/splunk-enterprise/leverage-rest-apis/rest-api-reference/10.2/introduction/endpoints-reference-list
  - type: Authentication
    url: https://docs.splunk.com/Documentation/Splunk/latest/RESTUM/RESTusing
  - type: Documentation
    url: https://docs.splunk.com/Documentation/Splunk/latest/RESTREF/RESTsearch
  - type: JSONSchema
    url: json-schema/splunk-search-job-schema.json
  - type: JSONSchema
    url: json-schema/splunk-event-schema.json
  - type: JSONLD
    url: json-ld/splunk-context.jsonld
- aid: splunk:splunk-index-api
  name: Splunk Index API
  description: Endpoints for managing Splunk indexes, which store and organize ingested data. Indexes can be created, modified,
    listed, and configured for retention and storage policies.
  humanURL: https://www.splunk.com/en_us/blog/learn/api-monitoring.html
  tags:
  - Index
  properties:
  - type: OpenAPI
    url: openapi/splunk-index-api-openapi.yml
  - type: Documentation
    url: https://docs.splunk.com/Documentation/Splunk/latest/RESTREF/RESTprolog
  - type: GettingStarted
    url: https://docs.splunk.com/Documentation/Splunk/latest/RESTUM/RESTusing
  - type: APIReference
    url: https://dev.splunk.com/enterprise/reference
  - type: APIReference
    url: https://help.splunk.com/en/splunk-enterprise/leverage-rest-apis/rest-api-reference/10.2/introduction/endpoints-reference-list
  - type: Authentication
    url: https://docs.splunk.com/Documentation/Splunk/latest/RESTUM/RESTusing
  - type: Documentation
    url: https://docs.splunk.com/Documentation/Splunk/latest/RESTREF/RESTsearch
  - type: JSONSchema
    url: json-schema/splunk-search-job-schema.json
  - type: JSONSchema
    url: json-schema/splunk-event-schema.json
  - type: JSONLD
    url: json-ld/splunk-context.jsonld
- aid: splunk:splunk-search-api
  name: Splunk Search API
  description: Endpoints for creating, managing, and retrieving search jobs and their results. Splunk search processing language
    (SPL) queries are submitted as search jobs that run asynchronously.
  humanURL: https://www.splunk.com/en_us/blog/learn/api-monitoring.html
  tags:
  - Search
  properties:
  - type: OpenAPI
    url: openapi/splunk-search-api-openapi.yml
  - type: Documentation
    url: https://docs.splunk.com/Documentation/Splunk/latest/RESTREF/RESTprolog
  - type: GettingStarted
    url: https://docs.splunk.com/Documentation/Splunk/latest/RESTUM/RESTusing
  - type: APIReference
    url: https://dev.splunk.com/enterprise/reference
  - type: APIReference
    url: https://help.splunk.com/en/splunk-enterprise/leverage-rest-apis/rest-api-reference/10.2/introduction/endpoints-reference-list
  - type: Authentication
    url: https://docs.splunk.com/Documentation/Splunk/latest/RESTUM/RESTusing
  - type: Documentation
    url: https://docs.splunk.com/Documentation/Splunk/latest/RESTREF/RESTsearch
  - type: JSONSchema
    url: json-schema/splunk-search-job-schema.json
  - type: JSONSchema
    url: json-schema/splunk-event-schema.json
  - type: JSONLD
    url: json-ld/splunk-context.jsonld
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- name: Splunk Inc.
  email: devinfo@splunk.com
  url: https://www.splunk.com
common:
- type: AgenticAccess
  url: agentic-access/splunk-agentic-access.yml
- type: TrustCenter
  url: security/splunk-trust-center.yml
- type: VulnerabilityDisclosure
  url: security/splunk-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/splunk-domain-security.yml
- type: Authentication
  url: authentication/splunk-authentication.yml
- type: PostmanWorkspace
  url: https://www.postman.com/kinlaneapi/splunk/overview
- type: Arazzo
  url: arazzo/splunk-control-and-cleanup-search-workflow.yml
  name: Splunk Finalize, Read, and Clean Up a Search Job
- type: Arazzo
  url: arazzo/splunk-hec-ingest-and-acknowledge-workflow.yml
  name: Splunk HEC Ingest an Event and Confirm Indexing
- type: Arazzo
  url: arazzo/splunk-provision-index-and-monitor-workflow.yml
  name: Splunk Provision an Index and Attach a Monitor Input
- type: Arazzo
  url: arazzo/splunk-raw-ingest-and-search-workflow.yml
  name: Splunk Ingest Raw Data then Search for It
- type: Arazzo
  url: arazzo/splunk-run-search-job-workflow.yml
  name: Splunk Run a Search Job and Retrieve Results
- type: Arazzo
  url: arazzo/splunk-search-events-workflow.yml
  name: Splunk Search and Retrieve Raw Events
- type: DeveloperPortal
  url: https://dev.splunk.com/
- type: Blog
  url: https://www.splunk.com/en_us/blog
- type: Support
  url: https://www.splunk.com/en_us/support-and-services.html
- type: StatusPage
  url: https://www.splunk.com/en_us/customer-success/splunk-services-status.html
- type: Documentation
  url: https://community.splunk.com/
  title: Community
- type: GitHubOrganization
  url: https://github.com/splunk
- type: Documentation
  url: https://docs.splunk.com/Documentation
- type: Documentation
  url: https://help.splunk.com/en
  title: Help Center
- type: GettingStarted
  url: https://dev.splunk.com/enterprise/docs
- type: Documentation
  url: https://dev.splunk.com/enterprise/docs/devtools/
  title: Developer Tools
- type: Documentation
  url: https://dev.splunk.com/enterprise/downloads
  title: Downloads
- type: Marketplace
  url: https://splunkbase.splunk.com/
- type: Pricing
  url: https://www.splunk.com/en_us/products/pricing.html
- type: Signup
  url: https://www.splunk.com/en_us/download/splunk-cloud.html
- type: Signup
  url: https://dev.splunk.com/enterprise/dev_license/
  title: Developer License
- type: TermsOfService
  url: https://www.splunk.com/en_us/legal/terms/terms-of-use.html
- type: TermsOfService
  url: https://www.splunk.com/en_us/legal/splunk-general-terms.html
  title: General Terms
- type: ChangeLog
  url: https://help.splunk.com/en/splunk-enterprise/release-notes-and-updates
- type: Authentication
  url: https://docs.splunk.com/Documentation/Splunk/latest/RESTUM/RESTusing
- type: SDKs
  url: https://github.com/splunk/splunk-sdk-python
  title: Python SDK
- type: SDKs
  url: https://github.com/splunk/splunk-sdk-java
  title: Java SDK
- type: SDKs
  url: https://github.com/splunk/splunk-sdk-javascript
  title: JavaScript SDK
- type: SDKs
  url: https://github.com/splunk/splunk-sdk-csharp-pcl
  title: C# SDK
- type: SDKs
  url: https://dev.splunk.com/enterprise/docs/devtools/csharp
  title: C# SDK Documentation
- type: ChangeLog
  url: https://dev.splunk.com/enterprise/docs/whatsnew/
  title: What's New
- type: ChangeLog
  url: https://dev.splunk.com/enterprise/docs/relnotes
  title: Release Notes
- type: Documentation
  url: https://dev.splunk.com/enterprise/docs/devtools/customrestendpoints
  title: Custom REST Endpoints
- type: Authentication
  url: https://docs.splunk.com/Documentation/Splunk/latest/Security/UseAuthTokens
  title: Auth Tokens
- type: PrivacyPolicy
  url: https://www.splunk.com/en_us/legal/privacy-policy.html
- type: Security
  url: https://www.splunk.com/en_us/about-splunk/splunk-data-security-and-privacy.html
- type: GitHubRepository
  url: https://github.com/signalfx/splunk-otel-collector
  title: OpenTelemetry Collector
- type: LinkedIn
  url: https://www.linkedin.com/company/splunk
- type: X
  url: https://twitter.com/splunk
- type: SpectralRules
  url: rules/splunk-spectral-rules.yml
- type: Features
  url: https://www.splunk.com/en_us/products.html
  data:
  - 'Splunk (now Cisco): hundreds of services across Observability + SIEM'
  - 'Detailed pricing: see https://www.splunk.com/en_us/products/pricing.html'
  - 'Service: Splunk Enterprise / Cloud (data ingest)'
  - 'Service: Splunk Observability Cloud (APM, Logs, RUM, Synthetics)'
  - 'Service: Splunk SOAR'
  - 'Service: Splunk Enterprise Security (SIEM)'
  - 'Service: Splunk ITSI'
  - 'Service: Splunk SOC Platform'
  sources:
  - https://www.splunk.com/en_us/products/pricing.html
  - https://focus.finops.org/
  updated: '2026-05-04'
- type: UseCases
  url: https://www.splunk.com/en_us/solutions.html
  data:
  - name: Security Information and Event Management
    description: Centralize security event data for real-time threat detection, investigation, and compliance reporting.
  - name: IT Operations Monitoring
    description: Monitor infrastructure health, application performance, and service availability across hybrid environments.
  - name: Log Management
    description: Collect, index, and analyze log data from servers, applications, and network devices for troubleshooting.
  - name: Incident Response Automation
    description: Automate security incident triage, enrichment, and response using SOAR playbooks and integrations.
  - name: Application Performance Monitoring
    description: Trace application requests end-to-end to identify bottlenecks and optimize performance.
  - name: Compliance and Audit
    description: Generate compliance reports and audit trails from indexed data to meet regulatory requirements.
- type: Integrations
  url: https://splunkbase.splunk.com/
  data:
  - name: AWS
    description: Ingest and analyze AWS CloudTrail, CloudWatch, VPC Flow Logs, and other AWS service data.
  - name: Azure
    description: Collect and analyze Azure activity logs, metrics, and diagnostic data.
  - name: Google Cloud
    description: Ingest Google Cloud audit logs, metrics, and Pub/Sub messages for cloud monitoring.
  - name: Kubernetes
    description: Monitor Kubernetes clusters with metrics, logs, and events from containers and orchestration.
  - name: ServiceNow
    description: Integrate Splunk alerts and incidents with ServiceNow ITSM for ticketing and workflow automation.
  - name: PagerDuty
    description: Trigger PagerDuty incidents from Splunk alerts for on-call notification and escalation.
  - name: Cisco
    description: Collect and analyze Cisco network device logs, firewall events, and security telemetry.
  - name: CrowdStrike
    description: Ingest CrowdStrike Falcon endpoint detection data for correlated threat analysis.
- name: MCP Server
  url: https://github.com/splunk/splunk-mcp-server2
  type: MCPServer