Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk.
Click here for the latest version.

Access endpoint examples
admin/SAML-groups GET
XML
XML Request
curl -k -u admin:password https://localhost:8089/services/admin/SAML-groups
XML Response
<title>SAML-groups</title> <id>https://localhost:8089/services/admin/SAML-groups</id> <updated>2015-11-07T18:00:05-08:00</updated> <generator build="05ee6658a12a17d11f47076b544" version="20151021"/> <author> <name>Splunk</name> </author> <link href="/services/admin/SAML-groups/_new" rel="create"/> <link href="/services/admin/SAML-groups/_acl" rel="_acl"/> <opensearch:totalResults>4</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>admin</title> <id>https://localhost:8089/services/admin/SAML-groups/admin</id> <updated>2015-11-07T18:00:05-08:00</updated> <link href="/services/admin/SAML-groups/admin" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/admin/SAML-groups/admin" rel="list"/> <link href="/services/admin/SAML-groups/admin" rel="edit"/> <link href="/services/admin/SAML-groups/admin" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="roles"> <s:list> <s:item>sc_admin</s:item> </s:list> </s:key> </s:dict> </content> </entry> <entry> <title>employee</title> <id>https://localhost:8089/services/admin/SAML-groups/employee</id> <updated>2015-11-07T18:00:05-08:00</updated> <link href="/services/admin/SAML-groups/employee" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/admin/SAML-groups/employee" rel="list"/> <link href="/services/admin/SAML-groups/employee" rel="edit"/> <link href="/services/admin/SAML-groups/employee" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="roles"> <s:list> <s:item>user</s:item> </s:list> </s:key> </s:dict> </content> </entry> <entry> <title>power admin</title> <id>https://localhost:8089/services/admin/SAML-groups/power%20admin</id> <updated>2015-11-07T18:00:05-08:00</updated> <link href="/services/admin/SAML-groups/power%20admin" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/admin/SAML-groups/power%20admin" rel="list"/> <link href="/services/admin/SAML-groups/power%20admin" rel="edit"/> <link href="/services/admin/SAML-groups/power%20admin" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="roles"> <s:list> <s:item>power</s:item> </s:list> </s:key> </s:dict> </content> </entry> <entry> <title>user admin</title> <id>https://localhost:8089/services/admin/SAML-groups/user%20admin</id> <updated>2015-11-07T18:00:05-08:00</updated> <link href="/services/admin/SAML-groups/user%20admin" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/admin/SAML-groups/user%20admin" rel="list"/> <link href="/services/admin/SAML-groups/user%20admin" rel="edit"/> <link href="/services/admin/SAML-groups/user%20admin" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="roles"> <s:list> <s:item>power</s:item> </s:list> </s:key> </s:dict> </content> </entry>
admin/SAML-groups POST
XML
XML Request
curl -k -u admin:changeme https://localhost:8089/services/admin/SAML-groups -d name=Splunk -d roles=user
XML Response
<title>SAML-groups</title> <id>https://localhost:8089/services/admin/SAML-groups</id> <updated>2015-11-07T18:04:56-08:00</updated> <generator build="05ee6658a1d11f47076b549133a47050ca24" version="20151021"/> <author> <name>Splunk</name> </author> <link href="/services/admin/SAML-groups/_new" rel="create"/> <link href="/services/admin/SAML-groups/_acl" rel="_acl"/> <opensearch:totalResults>0</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/>
admin/SAML-groups DELETE
XML
XML Request
curl -k -u admin:password --request DELETE https://localhost:8089/services/admin/SAML-groups?name=group_to_delete
XML Response
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:s="http://dev.splunk.com/ns/rest" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/"> <title>SAML-groups</title> <id>https://localhost:8089/services/admin/SAML-groups</id> <updated>2015-11-07T18:04:25-08:00</updated> <generator build="05ee6658a12a17d11f47133a47050ca24" version="20151021"/> <author> <name>Splunk</name> </author> <link href="/services/admin/SAML-groups/_new" rel="create"/> <link href="/services/admin/SAML-groups/_acl" rel="_acl"/> <opensearch:totalResults>0</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> </feed>
admin/SAML-idp-metadata GET
XML
XML Request
curl -k -u admin:changeme https://localhost:8089/services/admin/SAML-idp-metadata
XML Response
<title>SAML-idp-metadata</title> <id>https://localhost:8089/services/admin/SAML-idp-metadata</id> <updated>2015-11-07T18:34:07-08:00</updated> <generator build="05ee6658a12a17d11f47076h3453ffdd50ca24" version="20151021"/> <author> <name>Splunk</name> </author> <link href="/services/admin/SAML-idp-metadata/_acl" rel="_acl"/> <opensearch:totalResults>1</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>idpMetadataPayload</title> <id>https://localhost:8089/services/admin/SAML-idp-metadata/idpMetadataPayload</id> <updated>2015-11-07T18:34:07-08:00</updated> <link href="/services/admin/SAML-idp-metadata/idpMetadataPayload" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/admin/SAML-idp-metadata/idpMetadataPayload" rel="list"/> <content type="text/xml"> <s:dict> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="idpCertificatePayload"><![CDATA[MIIDpjCCAo6gAwIBAgIGAU7gBZ6oMA0GCSqGSIb3DQEBBQUAMIGTMQswCQYDVQQGEwJVUzETMBEG A1UECAwKQ2FsaWZvcrterye444uIEZyYW5jaXNjbzENMAsGA1UECgwET2t0YTEU MBIGA1UECwwLU1NPUHJvdmlkZXIxFDASBgNVBAMMC3NwbHVua3Rlc3QxMRwwGgYJKoZIhvcNAQkB Fg1pbmZvQG9rdGEuY29tMB4XDTE1MDczMDE3MzEyMVoXDTQ1MDczMDE3MzIyMVowgZMxCzAJBgNV BAYTAlnJhbmNpc2NvMQ0wCwYD VQQKDARPa3RhMRQwEgYDVQQLDAtTU09Qcm92aWRlcjEUMBIGA1UEAwwLc3BsdW5rdGVzdDExHDAa BgkqhkiG9w0BCQEWDWluZm9Ab2t0YS5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB AQCQS0Zh/PCBRsbHkJhi6RtGSkEzFjPZyPyFr2ND9KysDf4WRgMiklOBdrlM/++BJkqPCTYFbt/L ZXnVqo7v9wJ538MrTp6o1iBi52zhpDnqAoOIrlSaB0PbbQVd/oz49YbEW6/ThsAMHdIyz3/CSqEM o6oD7GiQzoGH4jidhx1Gjgmfk2OdkKAnWQDmZGKAMHJQXtjfrUK3y0H5j2tla9iIPLUVDyopzWNa o8TKw68iWDZs9ZGrwu9ptF4fpjiaslkWp3oyO1FmAencabXMddFZ7HgVziI2TjbExNa+bzS9SUhY gZlf2meD/ib2ul6HVFKlVM0IJA56qWGImiJRzGj1AgMBAAEwDQYJKoZIhvcNAQEFBQADggEBAC+I 566v40xTMhFjTlF3sRGjbXQDnJGXcuF1GFkAp/IEmdo 7mawu7Z7qcHb2BcQiVViuHY5ON2O/gbz5ggDipc803JMD7dTtFxDthfZgvN1tE/nPNgx2QAKCADw FkhYwAf6R7zV1VvyRfUzmbbl6V9JZh7Mju0vFsVJUsGhsAqJfZWQ+QckedB/NIpr9OxBu4IYgMZ4 gbV4yQ+FaICBh/vpqrtp5KmIIp63gXuV+Lh71NW0dj8oty3JpJmjZEdwXPjBKp5Xx94KHiA7Esyh +7Zk/NK0PJTvlTrsyk+UIeSJZE473SdxI7A=]]></s:key> <s:key name="protocol_endpoints"> <s:dict> <s:key name="idpSLOUrl">https://test.example.com/app/example/exk4nkqqsypk32FMF0h7/slo/saml</s:key> <s:key name="idpSSOUrl">https://test.example.com/app/example/exk4nkqqsypk32FMF0h7/sso/saml</s:key> </s:dict> </s:key> <s:key name="signAuthnRequest">1</s:key> </s:dict> </content> </entry>
admin/SAML-sp-metadata GET
XML
XML Request
curl -k -u admin:changeme https://localhost:8089/services/admin/SAML-sp-metadata
XML Response
<title>SAML-sp-metadata</title> <id>https://localhost:8089/services/admin/SAML-sp-metadata</id> <updated>2015-12-16T13:47:39-08:00</updated> <generator build="d48f9f793521" version="6.4.0"/> <author> <name>Splunk</name> </author> <link href="/services/admin/SAML-sp-metadata/_acl" rel="_acl"/> <opensearch:totalResults>1</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>spMetadata</title> <id>https://localhost:8089/services/admin/SAML-sp-metadata/spMetadata</id> <updated>2015-12-16T13:47:39-08:00</updated> <link href="/services/admin/SAML-sp-metadata/spMetadata" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/admin/SAML-sp-metadata/spMetadata" rel="list"/> <content type="text/xml"> <s:dict> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="spMetadata"><![CDATA[<md:EntityDescriptor entityID="splunkEntityId" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"> <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol" AuthnRequestsSigned="true" WantAssertionsSigned="true"> <md:KeyDescriptor> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate> MIICLTCCAZYCCQDCCiSo4+bLSzANBgkqhkiG9w0BAQUFADB/MQswCQYDVQQGEwJV UzELMAkGA1UECAwCQ0ExFjAUBgNVBAcMDVNhbiBGcmFuY2lzY28xDzANBgNVBAoM BlNwbHVuazEXMBUGA1UEAwwOU3BsdW5rQ29tbW9uQ0ExITAfBgkqhkiG9w0BCQEW EnN1cHBvcnRAc3BsdW5rLmNvbTAeFw0xNTA3MjgxNjMzNDNaFw0xODA3MjcxNjMz NDNaMDcxIDAeBgNVBAMMF1NwbHVerTRer55ZlckRlZmF1bHRDZXJ0MRMwEQYDVQQK DApTcGx1bmtVc2VyMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCmxUfArn3l Pxn24lBl1pWDFg5VCB/f8IS7MlEFPJiepioAli+yE7exlzD0wRniw2Akiyg1Kbt9 zNe1z9Dxi1fEOailFaV5ryENabYgYJFJonZKWucNvWzde50Cn4fm1nNqVSZOH90F 9zTGCD7Kkem0hIqx506TI2C2dKP+cJWeWwIDAQABMA0GCSqGSIb3DQEBBQUAA4GB ADy75DKIegJo2ALOZsckvrllqGZ2+g/xBupuRBDBSRp9vs3VqN+wB39uDtMzXlZ1 u0J5OhPVMdqO0RJuYzZmFpAhCX4hFfsNeazfFzSK/DQCURvfYG4pZit3P8gJ6uDv 3OxcDGUorMNlGRRO61UAkrLUywE44MMs1jgidDw2QlMY </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</md:NameIDFormat> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="http://example-unix-58667/saml/logout" index="0"> </md:SingleLogoutService> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="http://example-unix-58667/saml/acs" index="0"> </md:AssertionConsumerService> </md:SPSSODescriptor> </md:EntityDescriptor> ]]></s:key> </s:dict> </content> </entry>
admin/SAML-user-role-map GET
XML
XML Request
curl -k -u admin:password https://localhost:8089/services/admin/SAML-user-role-map
XML Response
<title>SAML-user-role-map</title> <id>https://localhost:8089/services/admin/SAML-user-role-map</id> <updated>2015-11-07T17:34:12-08:00</updated> <generator build="05ee6658a12a17d11f47076b549133a47050ca24" version="20151021"/> <author> <name>Splunk</name> </author> <link href="/services/admin/SAML-user-role-map/_new" rel="create"/> <link href="/services/admin/SAML-user-role-map/_acl" rel="_acl"/> <opensearch:totalResults>3</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>samluser001@example.com</title> <id>https://localhost:8089/services/admin/SAML-user-role-map/samluser001%40example.com</id> <updated>2015-11-07T17:34:12-08:00</updated> <link href="/services/admin/SAML-user-role-map/samluser001%40example.com" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/admin/SAML-user-role-map/samluser001%40example.com" rel="list"/> <link href="/services/admin/SAML-user-role-map/samluser001%40example.com" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>sc_admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>sc_admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="roles"> <s:list> <s:item>sc_admin</s:item> <s:item>user</s:item> </s:list> </s:key> </s:dict> </content> </entry> <entry> <title>samluser002@example.com</title> <id>https://localhost:8089/services/admin/SAML-user-role-map/samluser002%40example.com</id> <updated>2015-11-07T17:34:12-08:00</updated> <link href="/services/admin/SAML-user-role-map/samluser002%40example.com" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/admin/SAML-user-role-map/samluser002%40example.com" rel="list"/> <link href="/services/admin/SAML-user-role-map/samluser002%40example.com" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>sc_admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>sc_admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="roles"> <s:list> <s:item>power</s:item> </s:list> </s:key> </s:dict> </content> </entry> <entry> <title>samluser003@example.com</title> <id>https://localhost:8089/services/admin/SAML-user-role-map/samluser003%40example.com</id> <updated>2015-11-07T17:34:12-08:00</updated> <link href="/services/admin/SAML-user-role-map/samluser003%40example.com" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/admin/SAML-user-role-map/samluser003%40example.com" rel="list"/> <link href="/services/admin/SAML-user-role-map/samluser003%40example.com" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>sc_admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>sc_admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="roles"> <s:list> <s:item>user</s:item> </s:list> </s:key> </s:dict> </content> </entry>
admin/SAML-user-role-map POST
XML
XML Request
curl -k -u admin:password https://localhost:8089/services/admin/SAML-user-role-map -d name=samluser004@example.foo -d roles=user
XML Response
<title>SAML-user-role-map</title> <id>https://localhost:8089/services/admin/SAML-user-role-map</id> <updated>2015-11-07T17:45:54-08:00</updated> <generator build="05ee6658a12a17d11f47076b549133a47050ca24" version="20151021"/> <author> <name>Splunk</name> </author> <link href="/services/admin/SAML-user-role-map/_new" rel="create"/> <link href="/services/admin/SAML-user-role-map/_acl" rel="_acl"/> <opensearch:totalResults>1</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>samluser004@example.foo</title> <id>https://localhost:8089/services/admin/SAML-user-role-map/samluser004%40example.foo</id> <updated>2015-11-07T17:45:54-08:00</updated> <link href="/services/admin/SAML-user-role-map/samluser004%40example.foo" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/admin/SAML-user-role-map/samluser004%40example.foo" rel="list"/> <link href="/services/admin/SAML-user-role-map/samluser004%40example.foo" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>sc_admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>sc_admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="roles"> <s:list> <s:item>user</s:item> </s:list> </s:key> </s:dict> </content> </entry>
admin/SAML-user-role-map DELETE
XML
XML Request
curl -k -u admin:password --request DELETE https://localhost:8089/services/admin/SAML-user-role-map/samluser004@example.com
XML Response
<title>SAML-user-role-map</title> <id>https://localhost:8089/services/admin/SAML-user-role-map</id> <updated>2015-11-07T17:46:26-08:00</updated> <generator build="05ee6658a12a17d11f47076b549133a47050ca24" version="20151021"/> <author> <name>Splunk</name> </author> <link href="/services/admin/SAML-user-role-map/_new" rel="create"/> <link href="/services/admin/SAML-user-role-map/_acl" rel="_acl"/> <opensearch:totalResults>3</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>samluser001@example.com</title> <id>https://localhost:8089/services/admin/SAML-user-role-map/samluser001%40example.com</id> <updated>2015-11-07T17:46:26-08:00</updated> <link href="/services/admin/SAML-user-role-map/samluser001%40example.com" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/admin/SAML-user-role-map/samluser001%40example.com" rel="list"/> <link href="/services/admin/SAML-user-role-map/samluser001%40example.com" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>sc_admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>sc_admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="roles"> <s:list> <s:item>sc_admin</s:item> <s:item>user</s:item> </s:list> </s:key> </s:dict> </content> </entry> <entry> <title>samluser002@example.com</title> <id>https://localhost:8089/services/admin/SAML-user-role-map/samluser002%40example.com</id> <updated>2015-11-07T17:46:26-08:00</updated> <link href="/services/admin/SAML-user-role-map/samluser002%40example.com" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/admin/SAML-user-role-map/samluser002%40example.com" rel="list"/> <link href="/services/admin/SAML-user-role-map/samluser002%40example.com" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>sc_admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>sc_admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="roles"> <s:list> <s:item>power</s:item> </s:list> </s:key> </s:dict> </content> </entry> <entry> <title>samluser003@example.com</title> <id>https://localhost:8089/services/admin/SAML-user-role-map/samluser003%40example.com</id> <updated>2015-11-07T17:46:26-08:00</updated> <link href="/services/admin/SAML-user-role-map/samluser003%40example.com" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/admin/SAML-user-role-map/samluser003%40example.com" rel="list"/> <link href="/services/admin/SAML-user-role-map/samluser003%40example.com" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>sc_admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>_spl_cloud</s:item> <s:item>_spl_cloud_user</s:item> <s:item>admin</s:item> <s:item>sc_admin</s:item> <s:item>spl_cloud_user</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="roles"> <s:list> <s:item>user</s:item> </s:list> </s:key> </s:dict> </content> </entry>
auth/login POST
XML
XML Request
curl -k -u admin:changeme https://localhost:8089/services/auth/login -d username=admin -d password=changeme
XML Response
<response> <sessionKey>192fd3e46a31246da7ea7f109e7f95fd</sessionKey> </response>
authentication/current-context GET
XML
XML Request
curl -k -u admin:changeme https://localhost:8089/services/authentication/current-context
XML Response
. . . <title>current-context</title> <id>https://localhost:8089/services/authentication/current-context</id> <updated>2014-06-30T11:26:19-07:00</updated> <generator build="200839" version="6.1"/> <author> <name>Splunk</name> </author> <opensearch:totalResults>1</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>context</title> <id>https://localhost:8089/services/authentication/current-context/context</id> <updated>2014-06-30T11:26:19-07:00</updated> <link href="/services/authentication/current-context/context" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authentication/current-context/context" rel="list"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list> <s:item>accelerate_datamodel</s:item> <s:item>accelerate_search</s:item> <s:item>admin_all_objects</s:item> <s:item>change_authentication</s:item> <s:item>change_own_password</s:item> <s:item>edit_deployment_client</s:item> <s:item>edit_deployment_server</s:item> <s:item>edit_dist_peer</s:item> <s:item>edit_forwarders</s:item> <s:item>edit_httpauths</s:item> <s:item>edit_input_defaults</s:item> <s:item>edit_monitor</s:item> <s:item>edit_roles</s:item> <s:item>edit_scripted</s:item> <s:item>edit_search_server</s:item> <s:item>edit_server</s:item> <s:item>edit_splunktcp</s:item> <s:item>edit_splunktcp_ssl</s:item> <s:item>edit_tcp</s:item> <s:item>edit_udp</s:item> <s:item>edit_user</s:item> <s:item>edit_view_html</s:item> <s:item>edit_web_settings</s:item> <s:item>edit_win_admon</s:item> <s:item>edit_win_eventlogs</s:item> <s:item>edit_win_perfmon</s:item> <s:item>edit_win_regmon</s:item> <s:item>edit_win_wmiconf</s:item> <s:item>embed_report</s:item> <s:item>get_diag</s:item> <s:item>get_metadata</s:item> <s:item>get_typeahead</s:item> <s:item>indexes_edit</s:item> <s:item>input_file</s:item> <s:item>license_edit</s:item> <s:item>license_tab</s:item> <s:item>list_deployment_client</s:item> <s:item>list_deployment_server</s:item> <s:item>list_forwarders</s:item> <s:item>list_httpauths</s:item> <s:item>list_inputs</s:item> <s:item>list_pdfserver</s:item> <s:item>list_win_localavailablelogs</s:item> <s:item>output_file</s:item> <s:item>request_remote_tok</s:item> <s:item>rest_apps_management</s:item> <s:item>rest_apps_view</s:item> <s:item>rest_properties_get</s:item> <s:item>rest_properties_set</s:item> <s:item>restart_splunkd</s:item> <s:item>rtsearch</s:item> <s:item>run_debug_commands</s:item> <s:item>schedule_rtsearch</s:item> <s:item>schedule_search</s:item> <s:item>search</s:item> <s:item>write_pdfserver</s:item> </s:list> </s:key> <s:key name="defaultApp">launcher</s:key> <s:key name="defaultAppIsUserOverride">1</s:key> <s:key name="defaultAppSourceRole">system</s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>*</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="email">changeme@example.com</s:key> <s:key name="password">********</s:key> <s:key name="realname">Administrator</s:key> <s:key name="restart_background_jobs">1</s:key> <s:key name="roles"> <s:list> <s:item>admin</s:item> </s:list> </s:key> <s:key name="type">Splunk</s:key> <s:key name="tz"></s:key> <s:key name="username">admin</s:key> </s:dict> </content> </entry>
authentication/httpauth-tokens GET
XML
XML Request
curl -k -u admin:changeme https://localhost:8089/services/authentication/httpauth-tokens
XML Response
. . . <title>httpauth-tokens</title> <id>https://localhost:8089/services/authentication/httpauth-tokens</id> <updated>2014-06-30T11:28:04-07:00</updated> <generator build="200839" version="6.1"/> <author> <name>Splunk</name> </author> <opensearch:totalResults>2</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>15a773187d3e4437cbe9809f41f23d8f</title> <id>https://localhost:8089/services/authentication/httpauth-tokens/15a773187d3e4437cbe9809f41f23d8f</id> <updated>2014-06-30T11:28:04-07:00</updated> <link href="/services/authentication/httpauth-tokens/15a773187d3e4437cbe9809f41f23d8f" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authentication/httpauth-tokens/15a773187d3e4437cbe9809f41f23d8f" rel="list"/> <link href="/services/authentication/httpauth-tokens/15a773187d3e4437cbe9809f41f23d8f" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="authString">vdZv2eB9F0842dyJhrIEiGNTcBMpBeGuwGPYxtGLKAESQkzjSjG7dbymQW58y^oI3kxYXWfK_Fd3cRGqwPQGp58RvEkzwCaC6PmQgCsK</s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="searchId"></s:key> <s:key name="timeAccessed">Mon Jun 30 11:28:04 2014</s:key> <s:key name="userName">admin</s:key> </s:dict> </content> </entry> <entry> <title>694ef5bda40ae8c4f59626671b5f0c9a</title> <id>https://localhost:8089/services/authentication/httpauth-tokens/694ef5bda40ae8c4f59626671b5f0c9a</id> <updated>2014-06-30T11:28:04-07:00</updated> <link href="/services/authentication/httpauth-tokens/694ef5bda40ae8c4f59626671b5f0c9a" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authentication/httpauth-tokens/694ef5bda40ae8c4f59626671b5f0c9a" rel="list"/> <link href="/services/authentication/httpauth-tokens/694ef5bda40ae8c4f59626671b5f0c9a" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="authString">1RU5vGFm2OPq29plLtvqlEB9xzPDLZ3AleUhE1bwPjIrKtvyLE4fODhs^TgI4_NamvVtqusj8GnnNxd5wBB1wT^qHXn1DOV7LcCvErpyTzOvISr^2TnKUC</s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="searchId"></s:key> <s:key name="timeAccessed">Mon Jun 30 11:26:09 2014</s:key> <s:key name="userName">splunk-system-user</s:key> </s:dict> </content> </entry>
authentication/httpauth-tokens/{name} DELETE
XML
XML Request
curl -k -u admin:changeme --request DELETE https://localhost:8089/services/authentication/httpauth-tokens/vdZv2eB9F0842dyJhrIEiGNTcBMpBeGuwGPYxtGLKAESQkzjSjG7dbymQW58y^oI3kxYXWfK_Fd3cRGqwPQGp58RvEkzwCaC6PmQgCsK
XML Response
. . . <title>httpauth-tokens</title> <id>https://localhost:8089/services/authentication/httpauth-tokens</id> <updated>2014-06-30T12:02:12-07:00</updated> <generator build="200839" version="6.1"/> <author> <name>Splunk</name> </author> <opensearch:totalResults>1</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>694ef5bda40ae8c4f59626671b5f0c9a</title> <id>https://localhost:8089/services/authentication/httpauth-tokens/694ef5bda40ae8c4f59626671b5f0c9a</id> <updated>2014-06-30T12:02:12-07:00</updated> <link href="/services/authentication/httpauth-tokens/694ef5bda40ae8c4f59626671b5f0c9a" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authentication/httpauth-tokens/694ef5bda40ae8c4f59626671b5f0c9a" rel="list"/> <link href="/services/authentication/httpauth-tokens/694ef5bda40ae8c4f59626671b5f0c9a" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="authString">1RU5vGFm2OPq29plLtvqlEB9xzPDLZ3AleUhE1bwPjIrKtvyLE4fODhs^TgI4_NamvVtqusj8GnnNxd5wBB1wT^qHXn1DOV7LcCvErpyTzOvISr^2TnKUC</s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="searchId"></s:key> <s:key name="timeAccessed">Mon Jun 30 11:42:31 2014</s:key> <s:key name="userName">splunk-system-user</s:key> </s:dict> </content> </entry>
authentication/httpauth-tokens/{name} GET
XML
XML Request
curl -k -u admin:changeme https://localhost:8089/services/authentication/httpauth-tokens/vdZv2eB9F0842dyJhrIEiGNTcBMpBeGuwGPYxtGLKAESQkzjSjG7dbymQW58y^oI3kxYXWfK_Fd3cRGqwPQGp58RvEkzwCaC6PmQgCsK
XML Response
. . . <title>httpauth-tokens</title> <id>https://localhost:8089/services/authentication/httpauth-tokens</id> <updated>2014-06-30T11:39:52-07:00</updated> <generator build="200839" version="6.1"/> <author> <name>Splunk</name> </author> <opensearch:totalResults>1</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>15a773187d3e4437cbe9809f41f23d8f</title> <id>https://localhost:8089/services/authentication/httpauth-tokens/15a773187d3e4437cbe9809f41f23d8f</id> <updated>2014-06-30T11:39:52-07:00</updated> <link href="/services/authentication/httpauth-tokens/15a773187d3e4437cbe9809f41f23d8f" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authentication/httpauth-tokens/15a773187d3e4437cbe9809f41f23d8f" rel="list"/> <link href="/services/authentication/httpauth-tokens/15a773187d3e4437cbe9809f41f23d8f" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="authString">vdZv2eB9F0842dyJhrIEiGNTcBMpBeGuwGPYxtGLKAESQkzjSjG7dbymQW58y^oI3kxYXWfK_Fd3cRGqwPQGp58RvEkzwCaC6PmQgCsK</s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="eai:attributes"> <s:dict> <s:key name="optionalFields"> <s:list/> </s:key> <s:key name="requiredFields"> <s:list/> </s:key> <s:key name="wildcardFields"> <s:list/> </s:key> </s:dict> </s:key> <s:key name="searchId"></s:key> <s:key name="timeAccessed">Mon Jun 30 11:39:52 2014</s:key> <s:key name="userName">admin</s:key> </s:dict> </content> </entry>
authentication/users GET
XML
XML Request
curl -k -u admin:changeme https://localhost:8089/services/authentication/users
XML Response
. . . <title>users</title> <id>https://localhost:8089/services/authentication/users</id> <updated>2014-06-30T12:27:48-07:00</updated> <generator build="200839" version="6.1"/> <author> <name>Splunk</name> </author> <link href="/services/authentication/users/_new" rel="create"/> <opensearch:totalResults>2</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>admin</title> <id>https://localhost:8089/services/authentication/users/admin</id> <updated>2014-06-30T12:27:48-07:00</updated> <link href="/services/authentication/users/admin" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authentication/users/admin" rel="list"/> <link href="/services/authentication/users/admin" rel="edit"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list> <s:item>accelerate_datamodel</s:item> <s:item>accelerate_search</s:item> <s:item>admin_all_objects</s:item> <s:item>change_authentication</s:item> <s:item>change_own_password</s:item> <s:item>edit_deployment_client</s:item> <s:item>edit_deployment_server</s:item> <s:item>edit_dist_peer</s:item> <s:item>edit_forwarders</s:item> <s:item>edit_httpauths</s:item> <s:item>edit_input_defaults</s:item> <s:item>edit_monitor</s:item> <s:item>edit_roles</s:item> <s:item>edit_scripted</s:item> <s:item>edit_search_server</s:item> <s:item>edit_server</s:item> <s:item>edit_splunktcp</s:item> <s:item>edit_splunktcp_ssl</s:item> <s:item>edit_tcp</s:item> <s:item>edit_udp</s:item> <s:item>edit_user</s:item> <s:item>edit_view_html</s:item> <s:item>edit_web_settings</s:item> <s:item>edit_win_admon</s:item> <s:item>edit_win_eventlogs</s:item> <s:item>edit_win_perfmon</s:item> <s:item>edit_win_regmon</s:item> <s:item>edit_win_wmiconf</s:item> <s:item>embed_report</s:item> <s:item>get_diag</s:item> <s:item>get_metadata</s:item> <s:item>get_typeahead</s:item> <s:item>indexes_edit</s:item> <s:item>input_file</s:item> <s:item>license_edit</s:item> <s:item>license_tab</s:item> <s:item>list_deployment_client</s:item> <s:item>list_deployment_server</s:item> <s:item>list_forwarders</s:item> <s:item>list_httpauths</s:item> <s:item>list_inputs</s:item> <s:item>list_pdfserver</s:item> <s:item>list_win_localavailablelogs</s:item> <s:item>output_file</s:item> <s:item>request_remote_tok</s:item> <s:item>rest_apps_management</s:item> <s:item>rest_apps_view</s:item> <s:item>rest_properties_get</s:item> <s:item>rest_properties_set</s:item> <s:item>restart_splunkd</s:item> <s:item>rtsearch</s:item> <s:item>run_debug_commands</s:item> <s:item>schedule_rtsearch</s:item> <s:item>schedule_search</s:item> <s:item>search</s:item> <s:item>write_pdfserver</s:item> </s:list> </s:key> <s:key name="defaultApp">launcher</s:key> <s:key name="defaultAppIsUserOverride">1</s:key> <s:key name="defaultAppSourceRole">system</s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>*</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="email">changeme@example.com</s:key> <s:key name="password">********</s:key> <s:key name="realname">Administrator</s:key> <s:key name="restart_background_jobs">1</s:key> <s:key name="roles"> <s:list> <s:item>admin</s:item> </s:list> </s:key> <s:key name="type">Splunk</s:key> <s:key name="tz"></s:key> </s:dict> </content> </entry> <entry> <title>user1</title> <id>https://localhost:8089/services/authentication/users/user1</id> <updated>2014-06-30T12:27:48-07:00</updated> <link href="/services/authentication/users/user1" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authentication/users/user1" rel="list"/> <link href="/services/authentication/users/user1" rel="edit"/> <link href="/services/authentication/users/user1" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list> <s:item>accelerate_datamodel</s:item> <s:item>accelerate_search</s:item> <s:item>admin_all_objects</s:item> <s:item>change_authentication</s:item> <s:item>change_own_password</s:item> <s:item>edit_deployment_client</s:item> <s:item>edit_deployment_server</s:item> <s:item>edit_dist_peer</s:item> <s:item>edit_forwarders</s:item> <s:item>edit_httpauths</s:item> <s:item>edit_input_defaults</s:item> <s:item>edit_monitor</s:item> <s:item>edit_roles</s:item> <s:item>edit_scripted</s:item> <s:item>edit_search_server</s:item> <s:item>edit_server</s:item> <s:item>edit_splunktcp</s:item> <s:item>edit_splunktcp_ssl</s:item> <s:item>edit_tcp</s:item> <s:item>edit_udp</s:item> <s:item>edit_user</s:item> <s:item>edit_view_html</s:item> <s:item>edit_web_settings</s:item> <s:item>edit_win_admon</s:item> <s:item>edit_win_eventlogs</s:item> <s:item>edit_win_perfmon</s:item> <s:item>edit_win_regmon</s:item> <s:item>edit_win_wmiconf</s:item> <s:item>embed_report</s:item> <s:item>get_diag</s:item> <s:item>get_metadata</s:item> <s:item>get_typeahead</s:item> <s:item>indexes_edit</s:item> <s:item>input_file</s:item> <s:item>license_edit</s:item> <s:item>license_tab</s:item> <s:item>list_deployment_client</s:item> <s:item>list_deployment_server</s:item> <s:item>list_forwarders</s:item> <s:item>list_httpauths</s:item> <s:item>list_inputs</s:item> <s:item>list_pdfserver</s:item> <s:item>list_win_localavailablelogs</s:item> <s:item>output_file</s:item> <s:item>request_remote_tok</s:item> <s:item>rest_apps_management</s:item> <s:item>rest_apps_view</s:item> <s:item>rest_properties_get</s:item> <s:item>rest_properties_set</s:item> <s:item>restart_splunkd</s:item> <s:item>rtsearch</s:item> <s:item>run_debug_commands</s:item> <s:item>schedule_rtsearch</s:item> <s:item>schedule_search</s:item> <s:item>search</s:item> <s:item>write_pdfserver</s:item> </s:list> </s:key> <s:key name="defaultApp">launcher</s:key> <s:key name="defaultAppIsUserOverride">0</s:key> <s:key name="defaultAppSourceRole">system</s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>*</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="email"></s:key> <s:key name="password">********</s:key> <s:key name="realname"></s:key> <s:key name="restart_background_jobs">1</s:key> <s:key name="roles"> <s:list> <s:item>admin</s:item> </s:list> </s:key> <s:key name="type">Splunk</s:key> <s:key name="tz"></s:key> </s:dict> </content> </entry>
authentication/users POST
XML
XML Request
curl -k -u admin:changeme https://localhost:8089/services/authentication/users -d name=User1 -d password=changeme -d roles=admin
XML Response
<title>users</title> <id>https://localhost:8089/services/authentication/users</id> <updated>2014-06-30T12:18:19-07:00</updated> <generator build="200839" version="6.1"/> <author> <name>Splunk</name> </author> <link href="/services/authentication/users/_new" rel="create"/> <opensearch:totalResults>1</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>user1</title> <id>https://localhost:8089/services/authentication/users/user1</id> <updated>2014-06-30T12:18:19-07:00</updated> <link href="/services/authentication/users/user1" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authentication/users/user1" rel="list"/> <link href="/services/authentication/users/user1" rel="edit"/> <link href="/services/authentication/users/user1" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list> <s:item>accelerate_datamodel</s:item> <s:item>accelerate_search</s:item> <s:item>admin_all_objects</s:item> <s:item>change_authentication</s:item> <s:item>change_own_password</s:item> <s:item>edit_deployment_client</s:item> <s:item>edit_deployment_server</s:item> <s:item>edit_dist_peer</s:item> <s:item>edit_forwarders</s:item> <s:item>edit_httpauths</s:item> <s:item>edit_input_defaults</s:item> <s:item>edit_monitor</s:item> <s:item>edit_roles</s:item> <s:item>edit_scripted</s:item> <s:item>edit_search_server</s:item> <s:item>edit_server</s:item> <s:item>edit_splunktcp</s:item> <s:item>edit_splunktcp_ssl</s:item> <s:item>edit_tcp</s:item> <s:item>edit_udp</s:item> <s:item>edit_user</s:item> <s:item>edit_view_html</s:item> <s:item>edit_web_settings</s:item> <s:item>edit_win_admon</s:item> <s:item>edit_win_eventlogs</s:item> <s:item>edit_win_perfmon</s:item> <s:item>edit_win_regmon</s:item> <s:item>edit_win_wmiconf</s:item> <s:item>embed_report</s:item> <s:item>get_diag</s:item> <s:item>get_metadata</s:item> <s:item>get_typeahead</s:item> <s:item>indexes_edit</s:item> <s:item>input_file</s:item> <s:item>license_edit</s:item> <s:item>license_tab</s:item> <s:item>list_deployment_client</s:item> <s:item>list_deployment_server</s:item> <s:item>list_forwarders</s:item> <s:item>list_httpauths</s:item> <s:item>list_inputs</s:item> <s:item>list_pdfserver</s:item> <s:item>list_win_localavailablelogs</s:item> <s:item>output_file</s:item> <s:item>request_remote_tok</s:item> <s:item>rest_apps_management</s:item> <s:item>rest_apps_view</s:item> <s:item>rest_properties_get</s:item> <s:item>rest_properties_set</s:item> <s:item>restart_splunkd</s:item> <s:item>rtsearch</s:item> <s:item>run_debug_commands</s:item> <s:item>schedule_rtsearch</s:item> <s:item>schedule_search</s:item> <s:item>search</s:item> <s:item>write_pdfserver</s:item> </s:list> </s:key> <s:key name="defaultApp">launcher</s:key> <s:key name="defaultAppIsUserOverride">0</s:key> <s:key name="defaultAppSourceRole">system</s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="email"></s:key> <s:key name="password">********</s:key> <s:key name="realname"></s:key> <s:key name="restart_background_jobs">1</s:key> <s:key name="roles"> <s:list> <s:item>admin</s:item> </s:list> </s:key> <s:key name="type">Splunk</s:key> <s:key name="tz"></s:key> </s:dict> </content> </entry>
authentication/users/{name} DELETE
XML
XML Request
curl -k -u admin:changeme --request DELETE https://localhost:8089/services/authentication/users/user1
XML Response
. . . <title>users</title> <id>https://localhost:8089/services/authentication/users</id> <updated>2014-06-30T12:51:09-07:00</updated> <generator build="200839" version="6.1"/> <author> <name>Splunk</name> </author> <link href="/services/authentication/users/_new" rel="create"/> <opensearch:totalResults>1</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>admin</title> <id>https://localhost:8089/services/authentication/users/admin</id> <updated>2014-06-30T12:51:09-07:00</updated> <link href="/services/authentication/users/admin" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authentication/users/admin" rel="list"/> <link href="/services/authentication/users/admin" rel="edit"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list> <s:item>accelerate_datamodel</s:item> <s:item>accelerate_search</s:item> <s:item>admin_all_objects</s:item> <s:item>change_authentication</s:item> <s:item>change_own_password</s:item> <s:item>edit_deployment_client</s:item> <s:item>edit_deployment_server</s:item> <s:item>edit_dist_peer</s:item> <s:item>edit_forwarders</s:item> <s:item>edit_httpauths</s:item> <s:item>edit_input_defaults</s:item> <s:item>edit_monitor</s:item> <s:item>edit_roles</s:item> <s:item>edit_scripted</s:item> <s:item>edit_search_server</s:item> <s:item>edit_server</s:item> <s:item>edit_splunktcp</s:item> <s:item>edit_splunktcp_ssl</s:item> <s:item>edit_tcp</s:item> <s:item>edit_udp</s:item> <s:item>edit_user</s:item> <s:item>edit_view_html</s:item> <s:item>edit_web_settings</s:item> <s:item>edit_win_admon</s:item> <s:item>edit_win_eventlogs</s:item> <s:item>edit_win_perfmon</s:item> <s:item>edit_win_regmon</s:item> <s:item>edit_win_wmiconf</s:item> <s:item>embed_report</s:item> <s:item>get_diag</s:item> <s:item>get_metadata</s:item> <s:item>get_typeahead</s:item> <s:item>indexes_edit</s:item> <s:item>input_file</s:item> <s:item>license_edit</s:item> <s:item>license_tab</s:item> <s:item>list_deployment_client</s:item> <s:item>list_deployment_server</s:item> <s:item>list_forwarders</s:item> <s:item>list_httpauths</s:item> <s:item>list_inputs</s:item> <s:item>list_pdfserver</s:item> <s:item>list_win_localavailablelogs</s:item> <s:item>output_file</s:item> <s:item>request_remote_tok</s:item> <s:item>rest_apps_management</s:item> <s:item>rest_apps_view</s:item> <s:item>rest_properties_get</s:item> <s:item>rest_properties_set</s:item> <s:item>restart_splunkd</s:item> <s:item>rtsearch</s:item> <s:item>run_debug_commands</s:item> <s:item>schedule_rtsearch</s:item> <s:item>schedule_search</s:item> <s:item>search</s:item> <s:item>write_pdfserver</s:item> </s:list> </s:key> <s:key name="defaultApp">launcher</s:key> <s:key name="defaultAppIsUserOverride">1</s:key> <s:key name="defaultAppSourceRole">system</s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="email">changeme@example.com</s:key> <s:key name="password">********</s:key> <s:key name="realname">Administrator</s:key> <s:key name="restart_background_jobs">1</s:key> <s:key name="roles"> <s:list> <s:item>admin</s:item> </s:list> </s:key> <s:key name="type">Splunk</s:key> <s:key name="tz"></s:key> </s:dict> </content> </entry>
authentication/users/{name} GET
XML
XML Request
curl -k -u admin:changeme https://localhost:8089/services/authentication/users/user1
XML Response
. . . <title>users</title> <id>https://localhost:8089/services/authentication/users</id> <updated>2014-06-30T12:39:18-07:00</updated> <generator build="200839" version="6.1"/> <author> <name>Splunk</name> </author> <link href="/services/authentication/users/_new" rel="create"/> <opensearch:totalResults>1</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>user1</title> <id>https://localhost:8089/services/authentication/users/user1</id> <updated>2014-06-30T12:39:18-07:00</updated> <link href="/services/authentication/users/user1" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authentication/users/user1" rel="list"/> <link href="/services/authentication/users/user1" rel="edit"/> <link href="/services/authentication/users/user1" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list> <s:item>accelerate_datamodel</s:item> <s:item>accelerate_search</s:item> <s:item>admin_all_objects</s:item> <s:item>change_authentication</s:item> <s:item>change_own_password</s:item> <s:item>edit_deployment_client</s:item> <s:item>edit_deployment_server</s:item> <s:item>edit_dist_peer</s:item> <s:item>edit_forwarders</s:item> <s:item>edit_httpauths</s:item> <s:item>edit_input_defaults</s:item> <s:item>edit_monitor</s:item> <s:item>edit_roles</s:item> <s:item>edit_scripted</s:item> <s:item>edit_search_server</s:item> <s:item>edit_server</s:item> <s:item>edit_splunktcp</s:item> <s:item>edit_splunktcp_ssl</s:item> <s:item>edit_tcp</s:item> <s:item>edit_udp</s:item> <s:item>edit_user</s:item> <s:item>edit_view_html</s:item> <s:item>edit_web_settings</s:item> <s:item>edit_win_admon</s:item> <s:item>edit_win_eventlogs</s:item> <s:item>edit_win_perfmon</s:item> <s:item>edit_win_regmon</s:item> <s:item>edit_win_wmiconf</s:item> <s:item>embed_report</s:item> <s:item>get_diag</s:item> <s:item>get_metadata</s:item> <s:item>get_typeahead</s:item> <s:item>indexes_edit</s:item> <s:item>input_file</s:item> <s:item>license_edit</s:item> <s:item>license_tab</s:item> <s:item>list_deployment_client</s:item> <s:item>list_deployment_server</s:item> <s:item>list_forwarders</s:item> <s:item>list_httpauths</s:item> <s:item>list_inputs</s:item> <s:item>list_pdfserver</s:item> <s:item>list_win_localavailablelogs</s:item> <s:item>output_file</s:item> <s:item>request_remote_tok</s:item> <s:item>rest_apps_management</s:item> <s:item>rest_apps_view</s:item> <s:item>rest_properties_get</s:item> <s:item>rest_properties_set</s:item> <s:item>restart_splunkd</s:item> <s:item>rtsearch</s:item> <s:item>run_debug_commands</s:item> <s:item>schedule_rtsearch</s:item> <s:item>schedule_search</s:item> <s:item>search</s:item> <s:item>write_pdfserver</s:item> </s:list> </s:key> <s:key name="defaultApp">launcher</s:key> <s:key name="defaultAppIsUserOverride">0</s:key> <s:key name="defaultAppSourceRole">system</s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>*</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="eai:attributes"> <s:dict> <s:key name="optionalFields"> <s:list> <s:item>defaultApp</s:item> <s:item>email</s:item> <s:item>force-change-pass</s:item> <s:item>password</s:item> <s:item>realname</s:item> <s:item>restart_background_jobs</s:item> <s:item>roles</s:item> <s:item>tz</s:item> </s:list> </s:key> <s:key name="requiredFields"> <s:list/> </s:key> <s:key name="wildcardFields"> <s:list/> </s:key> </s:dict> </s:key> <s:key name="email"></s:key> <s:key name="password">********</s:key> <s:key name="realname"></s:key> <s:key name="restart_background_jobs">1</s:key> <s:key name="roles"> <s:list> <s:item>admin</s:item> </s:list> </s:key> <s:key name="type">Splunk</s:key> <s:key name="tz"></s:key> </s:dict> </content> </entry>
authentication/users/{name} POST
XML
XML Request
curl -k -u admin:changeme https://localhost:8089/services/authentication/users/user1 -d defaultApp=launcher
XML Response
. . . <title>users</title> <id>https://localhost:8089/services/authentication/users</id> <updated>2014-06-30T12:45:23-07:00</updated> <generator build="200839" version="6.1"/> <author> <name>Splunk</name> </author> <link href="/services/authentication/users/_new" rel="create"/> <opensearch:totalResults>1</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>user1</title> <id>https://localhost:8089/services/authentication/users/user1</id> <updated>2014-06-30T12:45:23-07:00</updated> <link href="/services/authentication/users/user1" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authentication/users/user1" rel="list"/> <link href="/services/authentication/users/user1" rel="edit"/> <link href="/services/authentication/users/user1" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list> <s:item>accelerate_datamodel</s:item> <s:item>accelerate_search</s:item> <s:item>admin_all_objects</s:item> <s:item>change_authentication</s:item> <s:item>change_own_password</s:item> <s:item>edit_deployment_client</s:item> <s:item>edit_deployment_server</s:item> <s:item>edit_dist_peer</s:item> <s:item>edit_forwarders</s:item> <s:item>edit_httpauths</s:item> <s:item>edit_input_defaults</s:item> <s:item>edit_monitor</s:item> <s:item>edit_roles</s:item> <s:item>edit_scripted</s:item> <s:item>edit_search_server</s:item> <s:item>edit_server</s:item> <s:item>edit_splunktcp</s:item> <s:item>edit_splunktcp_ssl</s:item> <s:item>edit_tcp</s:item> <s:item>edit_udp</s:item> <s:item>edit_user</s:item> <s:item>edit_view_html</s:item> <s:item>edit_web_settings</s:item> <s:item>edit_win_admon</s:item> <s:item>edit_win_eventlogs</s:item> <s:item>edit_win_perfmon</s:item> <s:item>edit_win_regmon</s:item> <s:item>edit_win_wmiconf</s:item> <s:item>embed_report</s:item> <s:item>get_diag</s:item> <s:item>get_metadata</s:item> <s:item>get_typeahead</s:item> <s:item>indexes_edit</s:item> <s:item>input_file</s:item> <s:item>license_edit</s:item> <s:item>license_tab</s:item> <s:item>list_deployment_client</s:item> <s:item>list_deployment_server</s:item> <s:item>list_forwarders</s:item> <s:item>list_httpauths</s:item> <s:item>list_inputs</s:item> <s:item>list_pdfserver</s:item> <s:item>list_win_localavailablelogs</s:item> <s:item>output_file</s:item> <s:item>request_remote_tok</s:item> <s:item>rest_apps_management</s:item> <s:item>rest_apps_view</s:item> <s:item>rest_properties_get</s:item> <s:item>rest_properties_set</s:item> <s:item>restart_splunkd</s:item> <s:item>rtsearch</s:item> <s:item>run_debug_commands</s:item> <s:item>schedule_rtsearch</s:item> <s:item>schedule_search</s:item> <s:item>search</s:item> <s:item>write_pdfserver</s:item> </s:list> </s:key> <s:key name="defaultApp">launcher</s:key> <s:key name="defaultAppIsUserOverride">1</s:key> <s:key name="defaultAppSourceRole">system</s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>*</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="email"></s:key> <s:key name="password">********</s:key> <s:key name="realname"></s:key> <s:key name="restart_background_jobs">1</s:key> <s:key name="roles"> <s:list> <s:item>admin</s:item> </s:list> </s:key> <s:key name="type">Splunk</s:key> <s:key name="tz"></s:key> </s:dict> </content> </entry>
authorization/capabilities GET
XML
XML Request
curl -k -u admin:changeme https://localhost:8089/services/authorization/capabilities
XML Response
. . . <title>capabilities</title> <id>https://localhost:8089/services/authorization/capabilities</id> <updated>2014-06-30T12:56:35-07:00</updated> <generator build="200839" version="6.1"/> <author> <name>Splunk</name> </author> <opensearch:totalResults>1</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>capabilities</title> <id>https://localhost:8089/services/authorization/capabilities/capabilities</id> <updated>2014-06-30T12:56:35-07:00</updated> <link href="/services/authorization/capabilities/capabilities" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authorization/capabilities/capabilities" rel="list"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list> <s:item>accelerate_datamodel</s:item> <s:item>accelerate_search</s:item> <s:item>admin_all_objects</s:item> <s:item>change_authentication</s:item> <s:item>change_own_password</s:item> <s:item>delete_by_keyword</s:item> <s:item>edit_deployment_client</s:item> <s:item>edit_deployment_server</s:item> <s:item>edit_dist_peer</s:item> <s:item>edit_forwarders</s:item> <s:item>edit_httpauths</s:item> <s:item>edit_input_defaults</s:item> <s:item>edit_monitor</s:item> <s:item>edit_roles</s:item> <s:item>edit_scripted</s:item> <s:item>edit_search_server</s:item> <s:item>edit_server</s:item> <s:item>edit_splunktcp</s:item> <s:item>edit_splunktcp_ssl</s:item> <s:item>edit_tcp</s:item> <s:item>edit_udp</s:item> <s:item>edit_user</s:item> <s:item>edit_view_html</s:item> <s:item>edit_web_settings</s:item> <s:item>edit_win_admon</s:item> <s:item>edit_win_eventlogs</s:item> <s:item>edit_win_perfmon</s:item> <s:item>edit_win_regmon</s:item> <s:item>edit_win_wmiconf</s:item> <s:item>embed_report</s:item> <s:item>get_diag</s:item> <s:item>get_metadata</s:item> <s:item>get_typeahead</s:item> <s:item>indexes_edit</s:item> <s:item>input_file</s:item> <s:item>license_edit</s:item> <s:item>license_tab</s:item> <s:item>list_deployment_client</s:item> <s:item>list_deployment_server</s:item> <s:item>list_forwarders</s:item> <s:item>list_httpauths</s:item> <s:item>list_inputs</s:item> <s:item>list_pdfserver</s:item> <s:item>list_win_localavailablelogs</s:item> <s:item>output_file</s:item> <s:item>request_remote_tok</s:item> <s:item>rest_apps_management</s:item> <s:item>rest_apps_view</s:item> <s:item>rest_properties_get</s:item> <s:item>rest_properties_set</s:item> <s:item>restart_splunkd</s:item> <s:item>rtsearch</s:item> <s:item>run_debug_commands</s:item> <s:item>schedule_rtsearch</s:item> <s:item>schedule_search</s:item> <s:item>search</s:item> <s:item>use_file_operator</s:item> <s:item>write_pdfserver</s:item> </s:list> </s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>*</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> </s:dict> </content> </entry>
authorization/grantable_capabilities GET
XML
XML Request
curl -k -u admin:changeme https://localhost:8089/services/authorization/grantable_capabilities
XML Response
<title>grantable_capabilities</title> <id>https://localhost:8089/services/authorization/grantable_capabilities</id> . . . <author> <name>Splunk</name> </author> <link href="/services/authorization/grantable_capabilities/_acl" rel="_acl"/> <opensearch:totalResults>1</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>capabilities</title> <id>https://localhost:8089/services/authorization/grantable_capabilities/capabilities</id> <updated>2015-10-06T17:44:09-07:00</updated> <link href="/services/authorization/grantable_capabilities/capabilities" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authorization/grantable_capabilities/capabilities" rel="list"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list> <s:item>accelerate_datamodel</s:item> <s:item>accelerate_search</s:item> <s:item>admin_all_objects</s:item> <s:item>change_authentication</s:item> <s:item>change_own_password</s:item> <s:item>delete_by_keyword</s:item> <s:item>edit_deployment_client</s:item> <s:item>edit_deployment_server</s:item> <s:item>edit_dist_peer</s:item> <s:item>edit_forwarders</s:item> <s:item>edit_httpauths</s:item> <s:item>edit_input_defaults</s:item> <s:item>edit_monitor</s:item> <s:item>edit_roles</s:item> <s:item>edit_roles_grantable</s:item> <s:item>edit_scripted</s:item> <s:item>edit_search_head_clustering</s:item> <s:item>edit_search_scheduler</s:item> <s:item>edit_search_server</s:item> <s:item>edit_server</s:item> <s:item>edit_sourcetypes</s:item> <s:item>edit_splunktcp</s:item> <s:item>edit_splunktcp_ssl</s:item> <s:item>edit_tcp</s:item> <s:item>edit_token_http</s:item> <s:item>edit_udp</s:item> <s:item>edit_user</s:item> <s:item>edit_view_html</s:item> <s:item>edit_web_settings</s:item> <s:item>embed_report</s:item> <s:item>get_diag</s:item> <s:item>get_metadata</s:item> <s:item>get_typeahead</s:item> <s:item>indexes_edit</s:item> <s:item>input_file</s:item> <s:item>license_edit</s:item> <s:item>license_tab</s:item> <s:item>license_view_warnings</s:item> <s:item>list_deployment_client</s:item> <s:item>list_deployment_server</s:item> <s:item>list_forwarders</s:item> <s:item>list_httpauths</s:item> <s:item>list_inputs</s:item> <s:item>list_introspection</s:item> <s:item>list_search_head_clustering</s:item> <s:item>list_search_scheduler</s:item> <s:item>output_file</s:item> <s:item>pattern_detect</s:item> <s:item>request_remote_tok</s:item> <s:item>rest_apps_management</s:item> <s:item>rest_apps_view</s:item> <s:item>rest_properties_get</s:item> <s:item>rest_properties_set</s:item> <s:item>restart_splunkd</s:item> <s:item>rtsearch</s:item> <s:item>run_debug_commands</s:item> <s:item>schedule_rtsearch</s:item> <s:item>schedule_search</s:item> <s:item>search</s:item> <s:item>use_file_operator</s:item> <s:item>web_debug</s:item> </s:list> </s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>*</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> </s:dict> </content> </entry>
authorization/roles GET
XML
XML Request
curl -k -u admin:changeme https://localhost:8089/services/authorization/roles
XML Response
. . . <title>roles</title> <id>https://localhost:8089/services/authorization/roles</id> <updated>2014-06-30T13:12:17-07:00</updated> <generator build="200839" version="6.1"/> <author> <name>Splunk</name> </author> <link href="/services/authorization/roles/_new" rel="create"/> <opensearch:totalResults>5</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>admin</title> <id>https://localhost:8089/services/authorization/roles/admin</id> <updated>2014-06-30T13:12:17-07:00</updated> <link href="/services/authorization/roles/admin" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authorization/roles/admin" rel="list"/> <link href="/services/authorization/roles/admin" rel="edit"/> <link href="/services/authorization/roles/admin" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list> <s:item>accelerate_datamodel</s:item> <s:item>admin_all_objects</s:item> <s:item>change_authentication</s:item> <s:item>edit_deployment_client</s:item> <s:item>edit_deployment_server</s:item> <s:item>edit_dist_peer</s:item> <s:item>edit_forwarders</s:item> <s:item>edit_httpauths</s:item> <s:item>edit_input_defaults</s:item> <s:item>edit_monitor</s:item> <s:item>edit_roles</s:item> <s:item>edit_scripted</s:item> <s:item>edit_search_server</s:item> <s:item>edit_server</s:item> <s:item>edit_splunktcp</s:item> <s:item>edit_splunktcp_ssl</s:item> <s:item>edit_tcp</s:item> <s:item>edit_udp</s:item> <s:item>edit_user</s:item> <s:item>edit_view_html</s:item> <s:item>edit_web_settings</s:item> <s:item>edit_win_admon</s:item> <s:item>edit_win_eventlogs</s:item> <s:item>edit_win_perfmon</s:item> <s:item>edit_win_regmon</s:item> <s:item>edit_win_wmiconf</s:item> <s:item>get_diag</s:item> <s:item>indexes_edit</s:item> <s:item>license_edit</s:item> <s:item>license_tab</s:item> <s:item>list_deployment_client</s:item> <s:item>list_deployment_server</s:item> <s:item>list_forwarders</s:item> <s:item>list_httpauths</s:item> <s:item>list_pdfserver</s:item> <s:item>list_win_localavailablelogs</s:item> <s:item>rest_apps_management</s:item> <s:item>restart_splunkd</s:item> <s:item>run_debug_commands</s:item> <s:item>write_pdfserver</s:item> </s:list> </s:key> <s:key name="cumulativeRTSrchJobsQuota">400</s:key> <s:key name="cumulativeSrchJobsQuota">200</s:key> <s:key name="defaultApp"></s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>*</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="imported_capabilities"> <s:list> <s:item>accelerate_search</s:item> <s:item>change_own_password</s:item> <s:item>embed_report</s:item> <s:item>get_metadata</s:item> <s:item>get_typeahead</s:item> <s:item>input_file</s:item> <s:item>list_inputs</s:item> <s:item>output_file</s:item> <s:item>request_remote_tok</s:item> <s:item>rest_apps_view</s:item> <s:item>rest_properties_get</s:item> <s:item>rest_properties_set</s:item> <s:item>rtsearch</s:item> <s:item>schedule_rtsearch</s:item> <s:item>schedule_search</s:item> <s:item>search</s:item> </s:list> </s:key> <s:key name="imported_roles"> <s:list> <s:item>power</s:item> <s:item>user</s:item> </s:list> </s:key> <s:key name="imported_rtSrchJobsQuota">20</s:key> <s:key name="imported_srchDiskQuota">500</s:key> <s:key name="imported_srchFilter"></s:key> <s:key name="imported_srchIndexesAllowed"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="imported_srchIndexesDefault"> <s:list> <s:item>main</s:item> </s:list> </s:key> <s:key name="imported_srchJobsQuota">10</s:key> <s:key name="imported_srchTimeWin">-1</s:key> <s:key name="rtSrchJobsQuota">100</s:key> <s:key name="srchDiskQuota">10000</s:key> <s:key name="srchFilter">*</s:key> <s:key name="srchIndexesAllowed"> <s:list> <s:item>*</s:item> <s:item>_*</s:item> </s:list> </s:key> <s:key name="srchIndexesDefault"> <s:list> <s:item>main</s:item> <s:item>os</s:item> </s:list> </s:key> <s:key name="srchJobsQuota">50</s:key> <s:key name="srchTimeWin">0</s:key> </s:dict> </content> </entry> <entry> <title>can_delete</title> <id>https://localhost:8089/services/authorization/roles/can_delete</id> <updated>2014-06-30T13:12:17-07:00</updated> <link href="/services/authorization/roles/can_delete" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authorization/roles/can_delete" rel="list"/> <link href="/services/authorization/roles/can_delete" rel="edit"/> <link href="/services/authorization/roles/can_delete" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list> <s:item>delete_by_keyword</s:item> <s:item>schedule_rtsearch</s:item> </s:list> </s:key> <s:key name="cumulativeRTSrchJobsQuota">0</s:key> <s:key name="cumulativeSrchJobsQuota">0</s:key> <s:key name="defaultApp"></s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>*</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="imported_capabilities"> <s:list/> </s:key> <s:key name="imported_roles"> <s:list/> </s:key> <s:key name="imported_rtSrchJobsQuota">0</s:key> <s:key name="imported_srchDiskQuota">0</s:key> <s:key name="imported_srchFilter"></s:key> <s:key name="imported_srchIndexesAllowed"> <s:list/> </s:key> <s:key name="imported_srchIndexesDefault"> <s:list/> </s:key> <s:key name="imported_srchJobsQuota">0</s:key> <s:key name="imported_srchTimeWin">-1</s:key> <s:key name="rtSrchJobsQuota">6</s:key> <s:key name="srchDiskQuota">100</s:key> <s:key name="srchFilter"></s:key> <s:key name="srchIndexesAllowed"> <s:list/> </s:key> <s:key name="srchIndexesDefault"> <s:list/> </s:key> <s:key name="srchJobsQuota">3</s:key> <s:key name="srchTimeWin">-1</s:key> </s:dict> </content> </entry> <entry> <title>power</title> <id>https://localhost:8089/services/authorization/roles/power</id> <updated>2014-06-30T13:12:17-07:00</updated> <link href="/services/authorization/roles/power" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authorization/roles/power" rel="list"/> <link href="/services/authorization/roles/power" rel="edit"/> <link href="/services/authorization/roles/power" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list> <s:item>embed_report</s:item> <s:item>rtsearch</s:item> <s:item>schedule_search</s:item> </s:list> </s:key> <s:key name="cumulativeRTSrchJobsQuota">200</s:key> <s:key name="cumulativeSrchJobsQuota">100</s:key> <s:key name="defaultApp"></s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>*</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="imported_capabilities"> <s:list> <s:item>accelerate_search</s:item> <s:item>change_own_password</s:item> <s:item>get_metadata</s:item> <s:item>get_typeahead</s:item> <s:item>input_file</s:item> <s:item>list_inputs</s:item> <s:item>output_file</s:item> <s:item>request_remote_tok</s:item> <s:item>rest_apps_view</s:item> <s:item>rest_properties_get</s:item> <s:item>rest_properties_set</s:item> <s:item>schedule_rtsearch</s:item> <s:item>search</s:item> </s:list> </s:key> <s:key name="imported_roles"> <s:list> <s:item>user</s:item> </s:list> </s:key> <s:key name="imported_rtSrchJobsQuota">6</s:key> <s:key name="imported_srchDiskQuota">100</s:key> <s:key name="imported_srchFilter"></s:key> <s:key name="imported_srchIndexesAllowed"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="imported_srchIndexesDefault"> <s:list> <s:item>main</s:item> </s:list> </s:key> <s:key name="imported_srchJobsQuota">3</s:key> <s:key name="imported_srchTimeWin">-1</s:key> <s:key name="rtSrchJobsQuota">20</s:key> <s:key name="srchDiskQuota">500</s:key> <s:key name="srchFilter"></s:key> <s:key name="srchIndexesAllowed"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="srchIndexesDefault"> <s:list> <s:item>main</s:item> </s:list> </s:key> <s:key name="srchJobsQuota">10</s:key> <s:key name="srchTimeWin">-1</s:key> </s:dict> </content> </entry> <entry> <title>splunk-system-role</title> <id>https://localhost:8089/services/authorization/roles/splunk-system-role</id> <updated>2014-06-30T13:12:17-07:00</updated> <link href="/services/authorization/roles/splunk-system-role" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authorization/roles/splunk-system-role" rel="list"/> <link href="/services/authorization/roles/splunk-system-role" rel="edit"/> <link href="/services/authorization/roles/splunk-system-role" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list/> </s:key> <s:key name="cumulativeRTSrchJobsQuota">100</s:key> <s:key name="cumulativeSrchJobsQuota">50</s:key> <s:key name="defaultApp"></s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>*</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="imported_capabilities"> <s:list> <s:item>accelerate_datamodel</s:item> <s:item>accelerate_search</s:item> <s:item>admin_all_objects</s:item> <s:item>change_authentication</s:item> <s:item>change_own_password</s:item> <s:item>edit_deployment_client</s:item> <s:item>edit_deployment_server</s:item> <s:item>edit_dist_peer</s:item> <s:item>edit_forwarders</s:item> <s:item>edit_httpauths</s:item> <s:item>edit_input_defaults</s:item> <s:item>edit_monitor</s:item> <s:item>edit_roles</s:item> <s:item>edit_scripted</s:item> <s:item>edit_search_server</s:item> <s:item>edit_server</s:item> <s:item>edit_splunktcp</s:item> <s:item>edit_splunktcp_ssl</s:item> <s:item>edit_tcp</s:item> <s:item>edit_udp</s:item> <s:item>edit_user</s:item> <s:item>edit_view_html</s:item> <s:item>edit_web_settings</s:item> <s:item>edit_win_admon</s:item> <s:item>edit_win_eventlogs</s:item> <s:item>edit_win_perfmon</s:item> <s:item>edit_win_regmon</s:item> <s:item>edit_win_wmiconf</s:item> <s:item>embed_report</s:item> <s:item>get_diag</s:item> <s:item>get_metadata</s:item> <s:item>get_typeahead</s:item> <s:item>indexes_edit</s:item> <s:item>input_file</s:item> <s:item>license_edit</s:item> <s:item>license_tab</s:item> <s:item>list_deployment_client</s:item> <s:item>list_deployment_server</s:item> <s:item>list_forwarders</s:item> <s:item>list_httpauths</s:item> <s:item>list_inputs</s:item> <s:item>list_pdfserver</s:item> <s:item>list_win_localavailablelogs</s:item> <s:item>output_file</s:item> <s:item>request_remote_tok</s:item> <s:item>rest_apps_management</s:item> <s:item>rest_apps_view</s:item> <s:item>rest_properties_get</s:item> <s:item>rest_properties_set</s:item> <s:item>restart_splunkd</s:item> <s:item>rtsearch</s:item> <s:item>run_debug_commands</s:item> <s:item>schedule_rtsearch</s:item> <s:item>schedule_search</s:item> <s:item>search</s:item> <s:item>write_pdfserver</s:item> </s:list> </s:key> <s:key name="imported_roles"> <s:list> <s:item>admin</s:item> </s:list> </s:key> <s:key name="imported_rtSrchJobsQuota">100</s:key> <s:key name="imported_srchDiskQuota">10000</s:key> <s:key name="imported_srchFilter">*</s:key> <s:key name="imported_srchIndexesAllowed"> <s:list> <s:item>*</s:item> <s:item>_*</s:item> </s:list> </s:key> <s:key name="imported_srchIndexesDefault"> <s:list> <s:item>main</s:item> <s:item>os</s:item> </s:list> </s:key> <s:key name="imported_srchJobsQuota">50</s:key> <s:key name="imported_srchTimeWin">-1</s:key> <s:key name="rtSrchJobsQuota">6</s:key> <s:key name="srchDiskQuota">100</s:key> <s:key name="srchFilter"></s:key> <s:key name="srchIndexesAllowed"> <s:list/> </s:key> <s:key name="srchIndexesDefault"> <s:list/> </s:key> <s:key name="srchJobsQuota">3</s:key> <s:key name="srchTimeWin">-1</s:key> </s:dict> </content> </entry> <entry> <title>user</title> <id>https://localhost:8089/services/authorization/roles/user</id> <updated>2014-06-30T13:12:17-07:00</updated> <link href="/services/authorization/roles/user" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authorization/roles/user" rel="list"/> <link href="/services/authorization/roles/user" rel="edit"/> <link href="/services/authorization/roles/user" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list> <s:item>accelerate_search</s:item> <s:item>change_own_password</s:item> <s:item>get_metadata</s:item> <s:item>get_typeahead</s:item> <s:item>input_file</s:item> <s:item>list_inputs</s:item> <s:item>output_file</s:item> <s:item>request_remote_tok</s:item> <s:item>rest_apps_view</s:item> <s:item>rest_properties_get</s:item> <s:item>rest_properties_set</s:item> <s:item>schedule_rtsearch</s:item> <s:item>search</s:item> </s:list> </s:key> <s:key name="cumulativeRTSrchJobsQuota">100</s:key> <s:key name="cumulativeSrchJobsQuota">50</s:key> <s:key name="defaultApp"></s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>*</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="imported_capabilities"> <s:list/> </s:key> <s:key name="imported_roles"> <s:list/> </s:key> <s:key name="imported_rtSrchJobsQuota">0</s:key> <s:key name="imported_srchDiskQuota">0</s:key> <s:key name="imported_srchFilter"></s:key> <s:key name="imported_srchIndexesAllowed"> <s:list/> </s:key> <s:key name="imported_srchIndexesDefault"> <s:list/> </s:key> <s:key name="imported_srchJobsQuota">0</s:key> <s:key name="imported_srchTimeWin">-1</s:key> <s:key name="rtSrchJobsQuota">6</s:key> <s:key name="srchDiskQuota">100</s:key> <s:key name="srchFilter"></s:key> <s:key name="srchIndexesAllowed"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="srchIndexesDefault"> <s:list> <s:item>main</s:item> </s:list> </s:key> <s:key name="srchJobsQuota">3</s:key> <s:key name="srchTimeWin">-1</s:key> </s:dict> </content> </entry>
authorization/roles POST
XML
XML Request
curl -k -u admin:changeme https://localhost:8089/services/authorization/roles -d name=newrole1 -d imported_roles=user
XML Response
. . . <title>roles</title> <id>https://localhost:8089/services/authorization/roles</id> <updated>2014-06-30T13:21:50-07:00</updated> <generator build="200839" version="6.1"/> <author> <name>Splunk</name> </author> <link href="/services/authorization/roles/_new" rel="create"/> <opensearch:totalResults>1</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>newrole1</title> <id>https://localhost:8089/services/authorization/roles/newrole1</id> <updated>2014-06-30T13:21:50-07:00</updated> <link href="/services/authorization/roles/newrole1" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authorization/roles/newrole1" rel="list"/> <link href="/services/authorization/roles/newrole1" rel="edit"/> <link href="/services/authorization/roles/newrole1" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list/> </s:key> <s:key name="cumulativeRTSrchJobsQuota">0</s:key> <s:key name="cumulativeSrchJobsQuota">0</s:key> <s:key name="defaultApp"></s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="imported_capabilities"> <s:list> <s:item>accelerate_search</s:item> <s:item>change_own_password</s:item> <s:item>get_metadata</s:item> <s:item>get_typeahead</s:item> <s:item>input_file</s:item> <s:item>list_inputs</s:item> <s:item>output_file</s:item> <s:item>request_remote_tok</s:item> <s:item>rest_apps_view</s:item> <s:item>rest_properties_get</s:item> <s:item>rest_properties_set</s:item> <s:item>schedule_rtsearch</s:item> <s:item>search</s:item> </s:list> </s:key> <s:key name="imported_roles"> <s:list> <s:item>user</s:item> </s:list> </s:key> <s:key name="imported_rtSrchJobsQuota">6</s:key> <s:key name="imported_srchDiskQuota">100</s:key> <s:key name="imported_srchFilter"></s:key> <s:key name="imported_srchIndexesAllowed"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="imported_srchIndexesDefault"> <s:list> <s:item>main</s:item> </s:list> </s:key> <s:key name="imported_srchJobsQuota">3</s:key> <s:key name="imported_srchTimeWin">-1</s:key> <s:key name="rtSrchJobsQuota">6</s:key> <s:key name="srchDiskQuota">100</s:key> <s:key name="srchFilter"></s:key> <s:key name="srchIndexesAllowed"> <s:list/> </s:key> <s:key name="srchIndexesDefault"> <s:list/> </s:key> <s:key name="srchJobsQuota">3</s:key> <s:key name="srchTimeWin">-1</s:key> </s:dict> </content> </entry>
authorization/roles/{name} DELETE
XML
XML Request
curl -k -u admin:changeme --request DELETE https://localhost:8089/services/authorization/roles/newrole1
XML Response
<title>roles</title> <id>https://localhost:8089/services/authorization/roles</id> <updated>2014-06-30T13:39:39-07:00</updated> <generator build="200839" version="6.1"/> <author> <name>Splunk</name> </author> <link href="/services/authorization/roles/_new" rel="create"/> <opensearch:totalResults>5</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>admin</title> <id>https://localhost:8089/services/authorization/roles/admin</id> <updated>2014-06-30T13:39:39-07:00</updated> <link href="/services/authorization/roles/admin" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authorization/roles/admin" rel="list"/> <link href="/services/authorization/roles/admin" rel="edit"/> <link href="/services/authorization/roles/admin" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list> <s:item>accelerate_datamodel</s:item> <s:item>admin_all_objects</s:item> <s:item>change_authentication</s:item> <s:item>edit_deployment_client</s:item> <s:item>edit_deployment_server</s:item> <s:item>edit_dist_peer</s:item> <s:item>edit_forwarders</s:item> <s:item>edit_httpauths</s:item> <s:item>edit_input_defaults</s:item> <s:item>edit_monitor</s:item> <s:item>edit_roles</s:item> <s:item>edit_scripted</s:item> <s:item>edit_search_server</s:item> <s:item>edit_server</s:item> <s:item>edit_splunktcp</s:item> <s:item>edit_splunktcp_ssl</s:item> <s:item>edit_tcp</s:item> <s:item>edit_udp</s:item> <s:item>edit_user</s:item> <s:item>edit_view_html</s:item> <s:item>edit_web_settings</s:item> <s:item>edit_win_admon</s:item> <s:item>edit_win_eventlogs</s:item> <s:item>edit_win_perfmon</s:item> <s:item>edit_win_regmon</s:item> <s:item>edit_win_wmiconf</s:item> <s:item>get_diag</s:item> <s:item>indexes_edit</s:item> <s:item>license_edit</s:item> <s:item>license_tab</s:item> <s:item>list_deployment_client</s:item> <s:item>list_deployment_server</s:item> <s:item>list_forwarders</s:item> <s:item>list_httpauths</s:item> <s:item>list_pdfserver</s:item> <s:item>list_win_localavailablelogs</s:item> <s:item>rest_apps_management</s:item> <s:item>restart_splunkd</s:item> <s:item>run_debug_commands</s:item> <s:item>write_pdfserver</s:item> </s:list> </s:key> <s:key name="cumulativeRTSrchJobsQuota">400</s:key> <s:key name="cumulativeSrchJobsQuota">200</s:key> <s:key name="defaultApp"></s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="imported_capabilities"> <s:list> <s:item>accelerate_search</s:item> <s:item>change_own_password</s:item> <s:item>embed_report</s:item> <s:item>get_metadata</s:item> <s:item>get_typeahead</s:item> <s:item>input_file</s:item> <s:item>list_inputs</s:item> <s:item>output_file</s:item> <s:item>request_remote_tok</s:item> <s:item>rest_apps_view</s:item> <s:item>rest_properties_get</s:item> <s:item>rest_properties_set</s:item> <s:item>rtsearch</s:item> <s:item>schedule_rtsearch</s:item> <s:item>schedule_search</s:item> <s:item>search</s:item> </s:list> </s:key> <s:key name="imported_roles"> <s:list> <s:item>power</s:item> <s:item>user</s:item> </s:list> </s:key> <s:key name="imported_rtSrchJobsQuota">20</s:key> <s:key name="imported_srchDiskQuota">500</s:key> <s:key name="imported_srchFilter"></s:key> <s:key name="imported_srchIndexesAllowed"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="imported_srchIndexesDefault"> <s:list> <s:item>main</s:item> </s:list> </s:key> <s:key name="imported_srchJobsQuota">10</s:key> <s:key name="imported_srchTimeWin">-1</s:key> <s:key name="rtSrchJobsQuota">100</s:key> <s:key name="srchDiskQuota">10000</s:key> <s:key name="srchFilter">*</s:key> <s:key name="srchIndexesAllowed"> <s:list> <s:item>*</s:item> <s:item>_*</s:item> </s:list> </s:key> <s:key name="srchIndexesDefault"> <s:list> <s:item>main</s:item> <s:item>os</s:item> </s:list> </s:key> <s:key name="srchJobsQuota">50</s:key> <s:key name="srchTimeWin">0</s:key> </s:dict> </content> </entry> <entry> <title>can_delete</title> <id>https://localhost:8089/services/authorization/roles/can_delete</id> <updated>2014-06-30T13:39:39-07:00</updated> <link href="/services/authorization/roles/can_delete" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authorization/roles/can_delete" rel="list"/> <link href="/services/authorization/roles/can_delete" rel="edit"/> <link href="/services/authorization/roles/can_delete" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list> <s:item>delete_by_keyword</s:item> <s:item>schedule_rtsearch</s:item> </s:list> </s:key> <s:key name="cumulativeRTSrchJobsQuota">0</s:key> <s:key name="cumulativeSrchJobsQuota">0</s:key> <s:key name="defaultApp"></s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="imported_capabilities"> <s:list/> </s:key> <s:key name="imported_roles"> <s:list/> </s:key> <s:key name="imported_rtSrchJobsQuota">0</s:key> <s:key name="imported_srchDiskQuota">0</s:key> <s:key name="imported_srchFilter"></s:key> <s:key name="imported_srchIndexesAllowed"> <s:list/> </s:key> <s:key name="imported_srchIndexesDefault"> <s:list/> </s:key> <s:key name="imported_srchJobsQuota">0</s:key> <s:key name="imported_srchTimeWin">-1</s:key> <s:key name="rtSrchJobsQuota">6</s:key> <s:key name="srchDiskQuota">100</s:key> <s:key name="srchFilter"></s:key> <s:key name="srchIndexesAllowed"> <s:list/> </s:key> <s:key name="srchIndexesDefault"> <s:list/> </s:key> <s:key name="srchJobsQuota">3</s:key> <s:key name="srchTimeWin">-1</s:key> </s:dict> </content> </entry> <entry> <title>power</title> <id>https://localhost:8089/services/authorization/roles/power</id> <updated>2014-06-30T13:39:39-07:00</updated> <link href="/services/authorization/roles/power" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authorization/roles/power" rel="list"/> <link href="/services/authorization/roles/power" rel="edit"/> <link href="/services/authorization/roles/power" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list> <s:item>embed_report</s:item> <s:item>rtsearch</s:item> <s:item>schedule_search</s:item> </s:list> </s:key> <s:key name="cumulativeRTSrchJobsQuota">200</s:key> <s:key name="cumulativeSrchJobsQuota">100</s:key> <s:key name="defaultApp"></s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="imported_capabilities"> <s:list> <s:item>accelerate_search</s:item> <s:item>change_own_password</s:item> <s:item>get_metadata</s:item> <s:item>get_typeahead</s:item> <s:item>input_file</s:item> <s:item>list_inputs</s:item> <s:item>output_file</s:item> <s:item>request_remote_tok</s:item> <s:item>rest_apps_view</s:item> <s:item>rest_properties_get</s:item> <s:item>rest_properties_set</s:item> <s:item>schedule_rtsearch</s:item> <s:item>search</s:item> </s:list> </s:key> <s:key name="imported_roles"> <s:list> <s:item>user</s:item> </s:list> </s:key> <s:key name="imported_rtSrchJobsQuota">6</s:key> <s:key name="imported_srchDiskQuota">100</s:key> <s:key name="imported_srchFilter"></s:key> <s:key name="imported_srchIndexesAllowed"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="imported_srchIndexesDefault"> <s:list> <s:item>main</s:item> </s:list> </s:key> <s:key name="imported_srchJobsQuota">3</s:key> <s:key name="imported_srchTimeWin">-1</s:key> <s:key name="rtSrchJobsQuota">20</s:key> <s:key name="srchDiskQuota">500</s:key> <s:key name="srchFilter"></s:key> <s:key name="srchIndexesAllowed"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="srchIndexesDefault"> <s:list> <s:item>main</s:item> </s:list> </s:key> <s:key name="srchJobsQuota">10</s:key> <s:key name="srchTimeWin">-1</s:key> </s:dict> </content> </entry> <entry> <title>splunk-system-role</title> <id>https://localhost:8089/services/authorization/roles/splunk-system-role</id> <updated>2014-06-30T13:39:39-07:00</updated> <link href="/services/authorization/roles/splunk-system-role" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authorization/roles/splunk-system-role" rel="list"/> <link href="/services/authorization/roles/splunk-system-role" rel="edit"/> <link href="/services/authorization/roles/splunk-system-role" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list/> </s:key> <s:key name="cumulativeRTSrchJobsQuota">100</s:key> <s:key name="cumulativeSrchJobsQuota">50</s:key> <s:key name="defaultApp"></s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="imported_capabilities"> <s:list> <s:item>accelerate_datamodel</s:item> <s:item>accelerate_search</s:item> <s:item>admin_all_objects</s:item> <s:item>change_authentication</s:item> <s:item>change_own_password</s:item> <s:item>edit_deployment_client</s:item> <s:item>edit_deployment_server</s:item> <s:item>edit_dist_peer</s:item> <s:item>edit_forwarders</s:item> <s:item>edit_httpauths</s:item> <s:item>edit_input_defaults</s:item> <s:item>edit_monitor</s:item> <s:item>edit_roles</s:item> <s:item>edit_scripted</s:item> <s:item>edit_search_server</s:item> <s:item>edit_server</s:item> <s:item>edit_splunktcp</s:item> <s:item>edit_splunktcp_ssl</s:item> <s:item>edit_tcp</s:item> <s:item>edit_udp</s:item> <s:item>edit_user</s:item> <s:item>edit_view_html</s:item> <s:item>edit_web_settings</s:item> <s:item>edit_win_admon</s:item> <s:item>edit_win_eventlogs</s:item> <s:item>edit_win_perfmon</s:item> <s:item>edit_win_regmon</s:item> <s:item>edit_win_wmiconf</s:item> <s:item>embed_report</s:item> <s:item>get_diag</s:item> <s:item>get_metadata</s:item> <s:item>get_typeahead</s:item> <s:item>indexes_edit</s:item> <s:item>input_file</s:item> <s:item>license_edit</s:item> <s:item>license_tab</s:item> <s:item>list_deployment_client</s:item> <s:item>list_deployment_server</s:item> <s:item>list_forwarders</s:item> <s:item>list_httpauths</s:item> <s:item>list_inputs</s:item> <s:item>list_pdfserver</s:item> <s:item>list_win_localavailablelogs</s:item> <s:item>output_file</s:item> <s:item>request_remote_tok</s:item> <s:item>rest_apps_management</s:item> <s:item>rest_apps_view</s:item> <s:item>rest_properties_get</s:item> <s:item>rest_properties_set</s:item> <s:item>restart_splunkd</s:item> <s:item>rtsearch</s:item> <s:item>run_debug_commands</s:item> <s:item>schedule_rtsearch</s:item> <s:item>schedule_search</s:item> <s:item>search</s:item> <s:item>write_pdfserver</s:item> </s:list> </s:key> <s:key name="imported_roles"> <s:list> <s:item>admin</s:item> </s:list> </s:key> <s:key name="imported_rtSrchJobsQuota">100</s:key> <s:key name="imported_srchDiskQuota">10000</s:key> <s:key name="imported_srchFilter">*</s:key> <s:key name="imported_srchIndexesAllowed"> <s:list> <s:item>*</s:item> <s:item>_*</s:item> </s:list> </s:key> <s:key name="imported_srchIndexesDefault"> <s:list> <s:item>main</s:item> <s:item>os</s:item> </s:list> </s:key> <s:key name="imported_srchJobsQuota">50</s:key> <s:key name="imported_srchTimeWin">-1</s:key> <s:key name="rtSrchJobsQuota">6</s:key> <s:key name="srchDiskQuota">100</s:key> <s:key name="srchFilter"></s:key> <s:key name="srchIndexesAllowed"> <s:list/> </s:key> <s:key name="srchIndexesDefault"> <s:list/> </s:key> <s:key name="srchJobsQuota">3</s:key> <s:key name="srchTimeWin">-1</s:key> </s:dict> </content> </entry> <entry> <title>user</title> <id>https://localhost:8089/services/authorization/roles/user</id> <updated>2014-06-30T13:39:39-07:00</updated> <link href="/services/authorization/roles/user" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authorization/roles/user" rel="list"/> <link href="/services/authorization/roles/user" rel="edit"/> <link href="/services/authorization/roles/user" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list> <s:item>accelerate_search</s:item> <s:item>change_own_password</s:item> <s:item>get_metadata</s:item> <s:item>get_typeahead</s:item> <s:item>input_file</s:item> <s:item>list_inputs</s:item> <s:item>output_file</s:item> <s:item>request_remote_tok</s:item> <s:item>rest_apps_view</s:item> <s:item>rest_properties_get</s:item> <s:item>rest_properties_set</s:item> <s:item>schedule_rtsearch</s:item> <s:item>search</s:item> </s:list> </s:key> <s:key name="cumulativeRTSrchJobsQuota">100</s:key> <s:key name="cumulativeSrchJobsQuota">50</s:key> <s:key name="defaultApp"></s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="imported_capabilities"> <s:list/> </s:key> <s:key name="imported_roles"> <s:list/> </s:key> <s:key name="imported_rtSrchJobsQuota">0</s:key> <s:key name="imported_srchDiskQuota">0</s:key> <s:key name="imported_srchFilter"></s:key> <s:key name="imported_srchIndexesAllowed"> <s:list/> </s:key> <s:key name="imported_srchIndexesDefault"> <s:list/> </s:key> <s:key name="imported_srchJobsQuota">0</s:key> <s:key name="imported_srchTimeWin">-1</s:key> <s:key name="rtSrchJobsQuota">6</s:key> <s:key name="srchDiskQuota">100</s:key> <s:key name="srchFilter"></s:key> <s:key name="srchIndexesAllowed"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="srchIndexesDefault"> <s:list> <s:item>main</s:item> </s:list> </s:key> <s:key name="srchJobsQuota">3</s:key> <s:key name="srchTimeWin">-1</s:key> </s:dict> </content> </entry>
authorization/roles/{name} GET
XML
XML Request
curl -k -u admin:changeme https://localhost:8089/services/authorization/roles/newrole1
XML Response
<title>roles</title> <id>https://localhost:8089/services/authorization/roles</id> <updated>2014-06-30T13:30:34-07:00</updated> <generator build="200839" version="6.1"/> <author> <name>Splunk</name> </author> <link href="/services/authorization/roles/_new" rel="create"/> <opensearch:totalResults>1</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>newrole1</title> <id>https://localhost:8089/services/authorization/roles/newrole1</id> <updated>2014-06-30T13:30:34-07:00</updated> <link href="/services/authorization/roles/newrole1" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authorization/roles/newrole1" rel="list"/> <link href="/services/authorization/roles/newrole1" rel="edit"/> <link href="/services/authorization/roles/newrole1" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list/> </s:key> <s:key name="cumulativeRTSrchJobsQuota">0</s:key> <s:key name="cumulativeSrchJobsQuota">0</s:key> <s:key name="defaultApp"></s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>*</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="eai:attributes"> <s:dict> <s:key name="optionalFields"> <s:list> <s:item>capabilities</s:item> <s:item>cumulativeRTSrchJobsQuota</s:item> <s:item>cumulativeSrchJobsQuota</s:item> <s:item>defaultApp</s:item> <s:item>imported_roles</s:item> <s:item>rtSrchJobsQuota</s:item> <s:item>srchDiskQuota</s:item> <s:item>srchFilter</s:item> <s:item>srchIndexesAllowed</s:item> <s:item>srchIndexesDefault</s:item> <s:item>srchJobsQuota</s:item> <s:item>srchTimeWin</s:item> </s:list> </s:key> <s:key name="requiredFields"> <s:list/> </s:key> <s:key name="wildcardFields"> <s:list/> </s:key> </s:dict> </s:key> <s:key name="imported_capabilities"> <s:list> <s:item>accelerate_search</s:item> <s:item>change_own_password</s:item> <s:item>get_metadata</s:item> <s:item>get_typeahead</s:item> <s:item>input_file</s:item> <s:item>list_inputs</s:item> <s:item>output_file</s:item> <s:item>request_remote_tok</s:item> <s:item>rest_apps_view</s:item> <s:item>rest_properties_get</s:item> <s:item>rest_properties_set</s:item> <s:item>schedule_rtsearch</s:item> <s:item>search</s:item> </s:list> </s:key> <s:key name="imported_roles"> <s:list> <s:item>user</s:item> </s:list> </s:key> <s:key name="imported_rtSrchJobsQuota">6</s:key> <s:key name="imported_srchDiskQuota">100</s:key> <s:key name="imported_srchFilter"></s:key> <s:key name="imported_srchIndexesAllowed"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="imported_srchIndexesDefault"> <s:list> <s:item>main</s:item> </s:list> </s:key> <s:key name="imported_srchJobsQuota">3</s:key> <s:key name="imported_srchTimeWin">-1</s:key> <s:key name="rtSrchJobsQuota">6</s:key> <s:key name="srchDiskQuota">100</s:key> <s:key name="srchFilter"></s:key> <s:key name="srchIndexesAllowed"> <s:list/> </s:key> <s:key name="srchIndexesDefault"> <s:list/> </s:key> <s:key name="srchJobsQuota">3</s:key> <s:key name="srchTimeWin">-1</s:key> </s:dict> </content> </entry>
authorization/roles/{name} POST
XML
XML Request
curl -k -u admin:changeme https://localhost:8089/services/authorization/roles/newrole1 -d defaultApp=launcher
XML Response
<title>roles</title> <id>https://localhost:8089/services/authorization/roles</id> <updated>2014-06-30T13:33:38-07:00</updated> <generator build="200839" version="6.1"/> <author> <name>Splunk</name> </author> <link href="/services/authorization/roles/_new" rel="create"/> <opensearch:totalResults>1</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>newrole1</title> <id>https://localhost:8089/services/authorization/roles/newrole1</id> <updated>2014-06-30T13:33:38-07:00</updated> <link href="/services/authorization/roles/newrole1" rel="alternate"/> <author> <name>system</name> </author> <link href="/services/authorization/roles/newrole1" rel="list"/> <link href="/services/authorization/roles/newrole1" rel="edit"/> <link href="/services/authorization/roles/newrole1" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="capabilities"> <s:list/> </s:key> <s:key name="cumulativeRTSrchJobsQuota">0</s:key> <s:key name="cumulativeSrchJobsQuota">0</s:key> <s:key name="defaultApp">launcher</s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app"></s:key> <s:key name="can_list">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">0</s:key> <s:key name="owner">system</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>admin</s:item> <s:item>splunk-system-role</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">0</s:key> <s:key name="sharing">system</s:key> </s:dict> </s:key> <s:key name="imported_capabilities"> <s:list> <s:item>accelerate_search</s:item> <s:item>change_own_password</s:item> <s:item>get_metadata</s:item> <s:item>get_typeahead</s:item> <s:item>input_file</s:item> <s:item>list_inputs</s:item> <s:item>output_file</s:item> <s:item>request_remote_tok</s:item> <s:item>rest_apps_view</s:item> <s:item>rest_properties_get</s:item> <s:item>rest_properties_set</s:item> <s:item>schedule_rtsearch</s:item> <s:item>search</s:item> </s:list> </s:key> <s:key name="imported_roles"> <s:list> <s:item>user</s:item> </s:list> </s:key> <s:key name="imported_rtSrchJobsQuota">6</s:key> <s:key name="imported_srchDiskQuota">100</s:key> <s:key name="imported_srchFilter"></s:key> <s:key name="imported_srchIndexesAllowed"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="imported_srchIndexesDefault"> <s:list> <s:item>main</s:item> </s:list> </s:key> <s:key name="imported_srchJobsQuota">3</s:key> <s:key name="imported_srchTimeWin">-1</s:key> <s:key name="rtSrchJobsQuota">6</s:key> <s:key name="srchDiskQuota">100</s:key> <s:key name="srchFilter"></s:key> <s:key name="srchIndexesAllowed"> <s:list/> </s:key> <s:key name="srchIndexesDefault"> <s:list/> </s:key> <s:key name="srchJobsQuota">3</s:key> <s:key name="srchTimeWin">-1</s:key> </s:dict> </content> </entry>
storage/passwords GET
XML
XML Request
curl -k -u admin:changeme https://localhost:8089/services/storage/passwords
XML Response
. . . <title>passwords</title> <id>https://localhost:8089/services/storage/passwords</id> <updated>2014-06-30T13:43:06-07:00</updated> <generator build="200839" version="6.1"/> <author> <name>Splunk</name> </author> <link href="/services/storage/passwords/_new" rel="create"/> <link href="/services/storage/passwords/_reload" rel="_reload"/> <opensearch:totalResults>1</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>:testuser:</title> <id>https://localhost:8089/servicesNS/nobody/search/storage/passwords/%3Atestuser%3A</id> <updated>2014-06-30T13:43:06-07:00</updated> <link href="/servicesNS/nobody/search/storage/passwords/%3Atestuser%3A" rel="alternate"/> <author> <name>admin</name> </author> <link href="/servicesNS/nobody/search/storage/passwords/%3Atestuser%3A" rel="list"/> <link href="/servicesNS/nobody/search/storage/passwords/%3Atestuser%3A/_reload" rel="_reload"/> <link href="/servicesNS/nobody/search/storage/passwords/%3Atestuser%3A" rel="edit"/> <link href="/servicesNS/nobody/search/storage/passwords/%3Atestuser%3A" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="clear_password">newpwd</s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app">search</s:key> <s:key name="can_change_perms">1</s:key> <s:key name="can_list">1</s:key> <s:key name="can_share_app">1</s:key> <s:key name="can_share_global">1</s:key> <s:key name="can_share_user">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">1</s:key> <s:key name="owner">admin</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>admin</s:item> <s:item>power</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">1</s:key> <s:key name="sharing">app</s:key> </s:dict> </s:key> <s:key name="encr_password">$1$prTUy3vRWg==</s:key> <s:key name="password">********</s:key> <s:key name="realm"></s:key> <s:key name="username">testuser</s:key> </s:dict> </content> </entry>
storage/passwords POST
XML
XML Request
curl -k -u admin:changeme https://localhost:8089/servicesNS/nobody/search/storage/passwords -d name=user1 -d password=changeme2
XML Response
. . . <title>passwords</title> <id>https://localhost:8089/services/storage/passwords</id> <updated>2014-06-30T13:51:44-07:00</updated> <generator build="200839" version="6.1"/> <author> <name>Splunk</name> </author> <link href="/services/storage/passwords/_new" rel="create"/> <link href="/services/storage/passwords/_reload" rel="_reload"/> <opensearch:totalResults>1</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>:user1:</title> <id>https://localhost:8089/servicesNS/nobody/search/storage/passwords/%3Auser1%3A</id> <updated>2014-06-30T13:51:44-07:00</updated> <link href="/servicesNS/nobody/search/storage/passwords/%3Auser1%3A" rel="alternate"/> <author> <name>admin</name> </author> <link href="/servicesNS/nobody/search/storage/passwords/%3Auser1%3A" rel="list"/> <link href="/servicesNS/nobody/search/storage/passwords/%3Auser1%3A/_reload" rel="_reload"/> <link href="/servicesNS/nobody/search/storage/passwords/%3Auser1%3A" rel="edit"/> <link href="/servicesNS/nobody/search/storage/passwords/%3Auser1%3A" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="clear_password">changeme2</s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app">search</s:key> <s:key name="can_change_perms">1</s:key> <s:key name="can_list">1</s:key> <s:key name="can_share_app">1</s:key> <s:key name="can_share_global">1</s:key> <s:key name="can_share_user">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">1</s:key> <s:key name="owner">admin</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>admin</s:item> <s:item>power</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">1</s:key> <s:key name="sharing">app</s:key> </s:dict> </s:key> <s:key name="encr_password">$1$q7nC1WvQY/pGcQ==</s:key> <s:key name="password">********</s:key> <s:key name="realm"></s:key> <s:key name="username">user1</s:key> </s:dict> </content> </entry>
storage/passwords/{name} DELETE
XML
XML Request
curl -k -u admin:changeme --request DELETE https://localhost:8089/servicesNS/nobody/search/storage/passwords/:user1:
XML Response
<title>passwords</title> <id>https://localhost:8089/services/storage/passwords</id> <updated>2014-06-30T14:21:11-07:00</updated> <generator build="200839" version="6.1"/> <author> <name>Splunk</name> </author> <link href="/services/storage/passwords/_new" rel="create"/> <link href="/services/storage/passwords/_reload" rel="_reload"/> <opensearch:totalResults>0</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/>
storage/passwords/{name} GET
XML
XML Request
curl -k -u admin:changeme https://localhost:8089/servicesNS/nobody/search/storage/passwords/user1
XML Response
<title>passwords</title> <id>https://localhost:8089/services/storage/passwords</id> <updated>2014-06-30T14:06:04-07:00</updated> <generator build="200839" version="6.1"/> <author> <name>Splunk</name> </author> <link href="/services/storage/passwords/_new" rel="create"/> <link href="/services/storage/passwords/_reload" rel="_reload"/> <opensearch:totalResults>1</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>:user1:</title> <id>https://localhost:8089/servicesNS/nobody/search/storage/passwords/%3Auser1%3A</id> <updated>2014-06-30T14:06:04-07:00</updated> <link href="/servicesNS/nobody/search/storage/passwords/%3Auser1%3A" rel="alternate"/> <author> <name>admin</name> </author> <link href="/servicesNS/nobody/search/storage/passwords/%3Auser1%3A" rel="list"/> <link href="/servicesNS/nobody/search/storage/passwords/%3Auser1%3A/_reload" rel="_reload"/> <link href="/servicesNS/nobody/search/storage/passwords/%3Auser1%3A" rel="edit"/> <link href="/servicesNS/nobody/search/storage/passwords/%3Auser1%3A" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="clear_password">changeme2</s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app">search</s:key> <s:key name="can_change_perms">1</s:key> <s:key name="can_list">1</s:key> <s:key name="can_share_app">1</s:key> <s:key name="can_share_global">1</s:key> <s:key name="can_share_user">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">1</s:key> <s:key name="owner">admin</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>admin</s:item> <s:item>power</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">1</s:key> <s:key name="sharing">app</s:key> </s:dict> </s:key> <s:key name="eai:attributes"> <s:dict> <s:key name="optionalFields"> <s:list/> </s:key> <s:key name="requiredFields"> <s:list> <s:item>password</s:item> </s:list> </s:key> <s:key name="wildcardFields"> <s:list/> </s:key> </s:dict> </s:key> <s:key name="encr_password">$1$q7nC1WvQY/pGcQ==</s:key> <s:key name="password">********</s:key> <s:key name="realm"></s:key> <s:key name="username">user1</s:key> </s:dict> </content> </entry>
storage/passwords/{name} POST
XML
XML Request
curl -k -u admin:changeme https://localhost:8089/servicesNS/nobody/search/storage/passwords/splunker -d password=changemeAgain
XML Response
. . . <title>passwords</title> <id>https://localhost:8089/services/storage/passwords</id> <updated>2014-06-30T14:13:57-07:00</updated> <generator build="200839" version="6.1"/> <author> <name>Splunk</name> </author> <link href="/services/storage/passwords/_new" rel="create"/> <link href="/services/storage/passwords/_reload" rel="_reload"/> <opensearch:totalResults>1</opensearch:totalResults> <opensearch:itemsPerPage>30</opensearch:itemsPerPage> <opensearch:startIndex>0</opensearch:startIndex> <s:messages/> <entry> <title>:user1:</title> <id>https://localhost:8089/servicesNS/nobody/search/storage/passwords/%3Auser1%3A</id> <updated>2014-06-30T14:13:57-07:00</updated> <link href="/servicesNS/nobody/search/storage/passwords/%3Auser1%3A" rel="alternate"/> <author> <name>admin</name> </author> <link href="/servicesNS/nobody/search/storage/passwords/%3Auser1%3A" rel="list"/> <link href="/servicesNS/nobody/search/storage/passwords/%3Auser1%3A/_reload" rel="_reload"/> <link href="/servicesNS/nobody/search/storage/passwords/%3Auser1%3A" rel="edit"/> <link href="/servicesNS/nobody/search/storage/passwords/%3Auser1%3A" rel="remove"/> <content type="text/xml"> <s:dict> <s:key name="clear_password">changemeAgain</s:key> <s:key name="eai:acl"> <s:dict> <s:key name="app">search</s:key> <s:key name="can_change_perms">1</s:key> <s:key name="can_list">1</s:key> <s:key name="can_share_app">1</s:key> <s:key name="can_share_global">1</s:key> <s:key name="can_share_user">1</s:key> <s:key name="can_write">1</s:key> <s:key name="modifiable">1</s:key> <s:key name="owner">admin</s:key> <s:key name="perms"> <s:dict> <s:key name="read"> <s:list> <s:item>*</s:item> </s:list> </s:key> <s:key name="write"> <s:list> <s:item>admin</s:item> <s:item>power</s:item> </s:list> </s:key> </s:dict> </s:key> <s:key name="removable">1</s:key> <s:key name="sharing">app</s:key> </s:dict> </s:key> <s:key name="encr_password">$1$q7nC1WvQY/p0UtMdIVM=</s:key> <s:key name="password">********</s:key> <s:key name="realm"></s:key> <s:key name="username">user1</s:key> </s:dict> </content> </entry>
Last modified on 21 April, 2017
PREVIOUS Access endpoint descriptions |
NEXT Application endpoint descriptions |
This documentation applies to the following versions of Splunk® Enterprise: 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11, 6.5.0, 6.5.1, 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.5.10
Feedback submitted, thanks!