Skip to main content
Splunk® Enterprise

REST API Reference Manual

Splunk® Enterprise
8.1.13
Splunk Enterprise version 8.1 will no longer be supported as of April 19, 2023. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.

License endpoint descriptions

Manage licensing configurations.

Usage details

Review ACL information for an endpoint

To check Access Control List (ACL) properties for an endpoint, append /acl to the path. For more information see Access Control List in the REST API User Manual.

Authentication and Authorization

Username and password authentication is required for access to endpoints and REST operations.

Splunk users must have role and/or capability-based authorization to use REST endpoints. Users with an administrative role, such as admin, can access authorization information in Splunk Web. To view the roles assigned to a user, select Settings > Access controls and click Users. To determine the capabilities assigned to a role, select Settings > Access controls and click Roles.

App and user context

Typically, knowledge objects, such as saved searches or event types, have an app/user context that is the namespace. For more information about specifying a namespace, see Namespace in the REST API User Manual.

Splunk Cloud Platform limitations

As a Splunk Cloud Platform user, you are restricted to interacting with the search tier only with the REST API. License endpoints are generally not accessible in Splunk Cloud Platform.

See Access requirements and limitations for the Splunk Cloud Platform REST API in the the REST API Tutorials manual for more information.


licenser/groups

https://<host>:<mPort>/services/licenser/groups

Provides access to the configuration of licenser groups.

A licenser group contains one or more licenser stacks that can operate concurrently. Only one licenser group is active at any given time.

GET

Expand

Lists all licenser groups.


licenser/groups/{name}

https://<host>:<mPort>/services/licenser/groups/{name}


Manage the {name} licenser group.


GET

Expand

List a specific licenser group.


POST

Expand

Activate a specific licenser group and deactivate the previously active one.



licenser/licenses

https://<host>:<mPort>/services/licenser/licenses


Provides access to the licenses for this Splunk Enterprise instance.

A license enables various features for a Splunk instance, including but not limited to indexing quota, auth, search, forwarding.


GET

Expand

List all licenses added.


POST

Expand

Add a license entitlement to the current instance.


licenser/licenses/{name}

https://<host>:<mPort>/services/licenser/licenses/{name}

Access or delete the {name} license.


DELETE

Expand

Delete the license with a hash corresponding to {name}


GET

Expand

List license details.


licenser/localslave

https://<host>:<mPort>/services/licenser/localslave

Get license state information for the Splunk instance.

GET

Expand

Get license state information for the Splunk instance.


licenser/messages

https://<host>:<mPort>/services/licenser/messages

Access licenser messages.

Messages may range from helpful warnings about being close to violations, licenses expiring or more severe alerts regarding overages and exceeding license warning window.


GET

Expand

List all messages/alerts/persisted warnings for this node.


licenser/messages/{name}

https://<host>:<mPort>/services/licenser/messages/{name}

Get the message with message ID {name}.


GET

Expand

List specific message whose msgId corresponds to {name} component.


licenser/pools

https://<host>:<mPort>/services/licenser/pools


Access the licenser pools configuration.

A pool logically partitions the daily volume entitlements of a stack. You can use a license pool to divide license privileges amongst multiple slaves.


GET

Expand

Enumerate all pools.


POST

Expand

Create a license pool.


licenser/pools/{name}

https://<host>:<mPort>/services/licenser/pools/{name}


Manage the {name} license pool.


DELETE

Expand

Delete the specified pool.


GET

Expand

Lists details of the pool specified by {name}.


POST

Expand

Edit properties of the pool specified by {name}.


licenser/slaves

https://<host>:<mPort>/services/licenser/slaves


Access license slave instances.


GET

Expand

List all slaves registered to this license master.


licenser/slaves/{name}

https://<host>:<mPort>/services/licenser/slaves/{name}


Get {name} licenser slave license information.


GET

Expand

List attributes of the slave instance specified by {name}.


licenser/stacks

https://<host>:<mPort>/services/licenser/stacks


Provides access to the license stack configuration.

A license stack is comprised of one or more licenses of the same "type". The daily indexing quota of a license stack is additive, so a stack represents the aggregate entitlement for a collection of licenses.

GET

Expand

Enumerate all license stacks.


licenser/stacks/{name}

https://<host>:<mPort>/services/licenser/stacks/{name}


Get {name} license stack information.


GET

Expand

Retrieve details of a specific license stack.


licenser/usage

https://<host>:<mPort>/services/licenser/usage


Get current license usage stats from the last minute.

GET

Expand

Enumerate license usage information from the last minute.


Last modified on 12 October, 2021
KV store endpoint descriptions   Metrics Catalog endpoint descriptions

This documentation applies to the following versions of Splunk® Enterprise: 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.11, 7.0.13, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.2.9, 7.2.10, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 7.3.9, 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.0.7, 8.0.8, 8.0.9, 8.0.10, 8.1.0, 8.1.1, 8.1.2, 8.1.3, 8.1.4, 8.1.5, 8.1.6, 8.1.7, 8.1.8, 8.1.9, 8.1.10, 8.1.11, 8.1.12, 8.1.13, 8.1.14, 8.2.0, 8.2.1, 8.2.2, 8.2.3, 8.2.4, 8.2.5, 8.2.6, 8.2.7, 8.2.8, 8.2.9, 8.2.10, 8.2.11, 8.2.12


Please expect delayed responses to documentation feedback while the team migrates content to a new system. We value your input and thank you for your patience as we work to provide you with an improved content experience!

Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters