Data Management Service API - Splunk Cloud Platform

Use the Data Management Service API to programmatically manage Edge Processor inventory, destinations, SPL2 pipeline lifecycle operations, and sourcetype synchronization on Splunk Cloud Platform.

Overview

The Data Management Service API provides REST endpoints for managing data orchestration resources in Splunk environments. Use these endpoints in automation workflows for Edge Processor inventory management, destination discovery, SPL2 pipeline lifecycle requests, and sourcetype synchronization.

With the Data Management Service API, you can integrate Edge Processor management, pipeline creation, pipeline updates, and deployment lifecycle requests into CI/CD pipelines, infrastructure-as-code tooling, or custom automation scripts. Pipelines can target Edge Processor and Ingest Processor runtimes and use SPL2 to define data transformations, source filters, and destination bindings.

What you can do with the Data Management Service API

The API reference is organized into the following resource categories:

Edge Processors
Use Edge Processor endpoints to create, list, retrieve, update, and delete Edge Processor resources. Use related endpoints to list Edge Processor instances, generate onboarding and offboarding scripts, and retrieve or update shared settings for source configurations used by Edge Processor deployments.
Destinations
Use destination endpoints to list destination-capable datasets that pipelines can route data into. Filter destinations by runtime when needed.
Pipelines
Use pipeline endpoints to create, list, retrieve, update, and delete SPL2 pipeline definitions for Edge Processor or Ingest Processor runtime environments. Define pipeline bodies, source filters, sample data, and destination parameter bindings. Submit requests to apply pipeline definitions, submit requests to cancel pipeline application, and retrieve pipeline deployment status.
Sourcetypes
Submit a request to start sourcetype synchronization from the search head to the cloud so pipeline workflows can use current sourcetype information.

Base URL

Use the following information to construct a Data Management Service API request URL:

  • Base URL:
    JSON
    https://{splunk_host}:{splunk_port}/servicesNS/{user}/dmx
  • Resource path: Append /v1/data/ and the resource path to access a Data Management Service operation.
  • splunk_host: Replace this variable with the search head hostname.
  • splunk_port: Replace this variable with the Splunk management port, which defaults to 8089.
  • user: Replace this variable with the Splunk user context that matches the authenticated caller.
  • OpenAPI document: Append /openapi/v1 to the base URL to retrieve the cached Data Management Service public OpenAPI document.

Authentication

All API requests require a bearer token in the Authorization header. Use a Splunk authentication token for the search head. For more information, see Use authentication tokens. Include the token in the following format:

CODE
Authorization: Bearer your-auth-token

Before you begin

To use the Data Management Service API with the Data Management APIs app, verify that you meet the following prerequisites:

  • You have access to the Data Management APIs app and the target Splunk search head.
  • You have a valid Splunk authentication token with the required app capabilities. Edge Processor and sourcetype operations require edit_edge_processor and edit_data_management_edgeprocessor. Destination operations require edit_datasets and edit_spl2_datasets. Pipeline definition operations require edit_data_management_pipeline; pipeline status and lifecycle operations require edit_data_management_pipeline_job.
  • You know the search head hostname, Splunk management port, and Splunk user context for the target environment.

Splunk Cloud version requirements

The Data Management Service API is available in Splunk Cloud when the Data Management app version is 10.1.2507 or later and the Splunk Cloud environment is running at least the applicable version listed here:

  • 10.1.2507.29
  • 10.2.2510.24
  • 10.3.2512.20
  • 10.4.2604.11
  • 10.5.2605.11
  • 10.6

Limitations

This API reference covers the Data Management Service API. Be aware of the following limitations:

  • API endpoints, request and response schemas, and behavior are subject to change in future releases.
  • The Data Management Service API depends on Splunk Cloud REST API access through TCP port 8089. If your environment blocks port 8089, you cannot use the Data Management Service API. Verify that port 8089 is permitted before using the API.
  • Destination endpoints are discovery-only. Use them to list destination-capable datasets for pipeline routing.
  • Pipeline create operations support EDGE and INGEST runtime values. The runtime is derived from the existing pipeline and cannot be changed when replacing a pipeline definition.