Product
Jentic OSThe workplace. An in-house AI platform for every employeeJentic OneSafe access. Agents reach your systems without holding keysJentic AIRThe foundation. Gets your existing platforms ready for AI
Pricing
Developers

GET STARTED

DocumentationGuides and API referenceQuickstartGet up and running in minutes

COMMUNITY

GitHubOpen source projects and examplesOpen StandardsBuilt on open specs. Never locked in.
Resources
Company
About UsOur mission and teamCareersJoin our teamContactGet in touch
Install Jentic OneBook a Demo
Jentic OSJentic OneJentic AIR
Pricing
DocumentationQuickstartGitHubOpen Standards
Resources
About UsCareersContact
Request a demoInstall Jentic One
JenticJentic
For Enterprises
  • Product Overview
  • Agentic Sandbox
  • Book a Demo
For Developers
  • Jentic One
  • Documentation
  • GitHub
Company
  • About Jentic
  • Careers
  • Contact Us
  • Trust Centre
ISO/IEC 27001:2022 certification badge issued by Prescient SecurityISO/IEC 27001:2022 certification badge issued by Prescient Security

Information Security Management System

Certified to ISO/IEC 27001:2022 by Prescient Security

Terms & Conditions•Privacy Policy•
© 2026 Jentic. All rights reserved.
Switch to light modeSwitch to dark mode
APIs / Cloud Infrastructure / Splunk Enterprise REST API
Splunk Enterprise REST API logo

Splunk Enterprise REST API

✓ Official Vendor SpecCloud InfrastructureComputeapiKey, basic95 EndpointsREST

For Agents

Programmatically authenticate and obtain a session token, create a new search job. Covers 95 operations with apiKey, basic authentication.

Use for: I need to authenticate and obtain a session token, I want to a new search job, Search for all search jobs, Find all search job status and details

Not supported: Does not handle payments, communications, or crm - use for cloud infrastructure only.

REST API for managing and interacting with Splunk Enterprise. Provides endpoints for search jobs, saved searches, indexes, data inputs/outputs, users, roles, apps, server management, and KV Store operations. The API exposes 95 endpoints secured with apiKey, basic authentication.

Jentic One on GithubView OpenAPI Document

Install Jentic One Beta

Connect the Splunk Enterprise REST API to your agent

Jentic One is a self-hosted execution layer for AI agents. It lets your agent call the Splunk Enterprise REST API, or any other public or private API you need. You set the rules, the agent never sees your credentials, and every call is logged.

Two steps, two machines. Install the instance in a safe environment, then register your agent from wherever it runs.

1

Step 1: Jentic One Host machine

# On the machine that will host your Jentic One instance:
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Fsplunk.com%2Fsplunk" | sh
2

Step 2: Agent machine

# On the machine where your agent runs (keep this separate from the instance):
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Fsplunk.com%2Fsplunk" | sh
jentic register       # connects your agent to your Jentic One instance

Jentic One is in public beta. The setup above keeps your agent separate from the instance, which is what you want before using real credentials: an agent running as the same OS user as Jentic One can read its stored keys directly. Just evaluating? A single local install is fine to start. See the secure deployment guide for the tiers.

Capabilities

What an agent can do with Splunk Enterprise REST API.

Authenticate and obtain a session token

Create a new search job

List all search jobs

Get search job status and details

Delete/cancel a search job

Control a search job (pause, unpause, finalize, cancel, etc.)

Use Cases

Patterns agents use Splunk Enterprise REST API for, with concrete tasks.

★ Cloud Infrastructure Operations

Use the Splunk Enterprise REST API to perform cloud infrastructure operations programmatically. The API provides 95 endpoints covering core functionality including authenticate and obtain a session token, create a new search job, list all search jobs.

Call POST /services/auth/login to authenticate and obtain a session token

Automated Authentication Management

Automate authentication operations by combining multiple Splunk Enterprise REST API endpoints. Agents can create a new search job and then list all search jobs in a single workflow.

Call POST /services/search/jobs to create a new search job, then verify the result

AI Agent Integration via Jentic

AI agents discover and call Splunk Enterprise REST API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle apiKey, basic tokens manually.

Search Jentic for 'authenticate and obtain a session token', load the operation schema, and execute with Jentic-managed credentials

Key Endpoints

95 endpoints — rest api for managing and interacting with splunk enterprise.

METHOD

PATH

DESCRIPTION

POST

/services/auth/login

Authenticate and obtain a session token

POST

/services/search/jobs

Create a new search job

GET

/services/search/jobs

List all search jobs

GET

/services/search/jobs/{search_id}

Get search job status and details

DELETE

/services/search/jobs/{search_id}

Delete/cancel a search job

POST

/services/search/jobs/{search_id}/control

Control a search job (pause, unpause, finalize, cancel, etc.)

GET

/services/search/jobs/{search_id}/results

Get final search results

GET

/services/search/jobs/{search_id}/results_preview

Get preview results from a running search

POST

/services/auth/login

Authenticate and obtain a session token

POST

/services/search/jobs

Create a new search job

GET

/services/search/jobs

List all search jobs

GET

/services/search/jobs/{search_id}

Get search job status and details

DELETE

/services/search/jobs/{search_id}

Delete/cancel a search job

POST

/services/search/jobs/{search_id}/control

Control a search job (pause, unpause, finalize, cancel, etc.)

GET

/services/search/jobs/{search_id}/results

Get final search results

GET

/services/search/jobs/{search_id}/results_preview

Get preview results from a running search

Why Jentic?

What agents get from Jentic-routed access to this vendor.

Setup

Setup

Wiring the Splunk Enterprise REST API by hand means handling its session-token or HTTP basic auth, calling /services/auth/login to mint a token, and pointing every call at your own {host}:8089 management port yourself. Through Jentic you install once, import the Splunk Enterprise REST API from the API Directory, store the credential once, and your agent calls it.

Permission scoping

Permission scoping

Splunk puts the search job id in the URL path (/services/search/jobs/{search_id}/...), so a rule can pin your agent to one search job and its results. You choose the operations it may call, so destructive ones like deleting a job or issuing control actions are not included unless you add them.

Credential management

Credential isolation

Your Splunk credential is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.

Intent-based discovery

Intent-based discovery

Agents search Jentic by intent such as 'run a search' or 'get search job results', and Jentic returns the matching Splunk Enterprise REST API operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

Related APIs

Alternatives and complements available in the Jentic catalogue.

Alternative

Amazonaws

→

Alternative cloud infrastructure API

Choose Amazonaws when you need a different approach to cloud infrastructure operations

Alternative

Azure

→

Alternative cloud infrastructure API

Choose Azure when you need a different approach to cloud infrastructure operations

Complementary

Googleapis

→

Complementary cloud infrastructure API

Choose Googleapis when you need a complementary approach to cloud infrastructure operations

Complementary

Digitalocean

→

Complementary cloud infrastructure API

Choose Digitalocean when you need a complementary approach to cloud infrastructure operations

FAQs

Specific to using Splunk Enterprise REST API through Jentic.

What authentication does the Splunk Enterprise REST API use?

The Splunk Enterprise REST API uses apiKey, basic authentication. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.

Can I authenticate and obtain a session token with the Splunk Enterprise REST API?

Yes. Use the POST /services/auth/login endpoint. The API returns structured JSON responses that agents can parse and act on directly.

What are the rate limits for the Splunk Enterprise REST API?

Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.

How do I authenticate and obtain a session token through Jentic?

Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'authenticate and obtain a session token'. Jentic returns the matching Splunk Enterprise REST API operation with its input schema. Load the schema and execute the call - credentials are injected automatically.

How many endpoints does the Splunk Enterprise REST API have?

The Splunk Enterprise REST API exposes 95 endpoints covering authentication, search jobs, saved searches operations.

Can I limit what my agent is allowed to do with the Splunk Enterprise REST API?

Yes. Jentic One is self-hosted, so your own rules decide which Splunk operations and credentials the agent may use. Because Splunk puts the search job id in the URL path (/services/search/jobs/{search_id}/...), you can pin the agent to a single search job and its results, and you choose exactly which operations it may call. Destructive actions like deleting a search job (DELETE /services/search/jobs/{search_id}) or issuing control actions (POST /services/search/jobs/{search_id}/control) stay out of reach unless you add them.

GET STARTED

Start building with Splunk Enterprise REST API

Explore with Jentic One
View OpenAPI Document