<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: REST Data Inputs in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/REST-Data-Inputs/m-p/387203#M47162</link>
    <description>&lt;P&gt;Any ideas?&lt;/P&gt;</description>
    <pubDate>Tue, 03 Jul 2018 15:58:16 GMT</pubDate>
    <dc:creator>Kendo213</dc:creator>
    <dc:date>2018-07-03T15:58:16Z</dc:date>
    <item>
      <title>REST Data Inputs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/REST-Data-Inputs/m-p/387200#M47159</link>
      <description>&lt;P&gt;I'm running Splunk Enterprise 6.6.4 and have several REST inputs added under Settings &amp;gt; Data Inputs &amp;gt; REST.&lt;/P&gt;

&lt;P&gt;I'm noticing in the internal logs that many other add-ons that also leverage rest API are attempting to make calls utilizing these inputs.  &lt;/P&gt;

&lt;P&gt;For example,  I have a REST input I created called 'Storage01CPU' that has an endpoint URL that goes directly to the storage array with parameters to pull in CPU usage.  We also have a Falcon Crowdstrike TA add-on installed (Splunk supported) on this search head that queries the Crowdstrike cloud API to pull in events.&lt;/P&gt;

&lt;P&gt;I see this in the _internal logs: splunk-system-user [18/Jun/2018:13:59:45.827 -0500] "GET /services/data/inputs/falcon_host_api/Storage01CPU HTTP/1.0" 404 155 - - - 76ms&lt;/P&gt;

&lt;P&gt;It's doing this for many other things as well, thus resulting in a ton of 404s.  Any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:01:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/REST-Data-Inputs/m-p/387200#M47159</guid>
      <dc:creator>Kendo213</dc:creator>
      <dc:date>2020-09-29T20:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: REST Data Inputs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/REST-Data-Inputs/m-p/387201#M47160</link>
      <description>&lt;P&gt;These are internal calls to Spunk's management REST API , not outgoing calls. Also, these are not logs generated by the REST API Mod Input.&lt;/P&gt;

&lt;P&gt;A 404 is "not found". It would appear that Splunk is trying to find an internal rest endpoint for a "Storage01CPU" stanza that lives in the "falcon_host_api" app context.&lt;/P&gt;

&lt;P&gt;When you setup your REST stanzas , under what app/user context did you create them ? ie: look where the inputs.conf file lives (find/grep for it on your filesystem).&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:01:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/REST-Data-Inputs/m-p/387201#M47160</guid>
      <dc:creator>Damien_Dallimor</dc:creator>
      <dc:date>2020-09-29T20:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: REST Data Inputs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/REST-Data-Inputs/m-p/387202#M47161</link>
      <description>&lt;P&gt;I was logged in as my admin account, and went to Settings &amp;gt; Data Inputs &amp;gt; REST &amp;gt; Add New&lt;/P&gt;

&lt;P&gt;I then added a new input per statistic I wanted to pull from the storage array.  It contacts the storage array using a service account.&lt;/P&gt;

&lt;P&gt;It shouldn't be in any way associated with any other app on the server ;\  I set a manual source type of dell:emc on the REST API input.  The inputs.conf is located in search/local/inputs.conf.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 13:08:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/REST-Data-Inputs/m-p/387202#M47161</guid>
      <dc:creator>Kendo213</dc:creator>
      <dc:date>2018-06-19T13:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: REST Data Inputs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/REST-Data-Inputs/m-p/387203#M47162</link>
      <description>&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jul 2018 15:58:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/REST-Data-Inputs/m-p/387203#M47162</guid>
      <dc:creator>Kendo213</dc:creator>
      <dc:date>2018-07-03T15:58:16Z</dc:date>
    </item>
    <item>
      <title>Re: REST Data Inputs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/REST-Data-Inputs/m-p/387204#M47163</link>
      <description>&lt;P&gt;Have you contacted Splunk support about the supported Falcon Crowdstrike TA add-on as your 404 error above is from this app's inputs (falcon_host_api)&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:16:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/REST-Data-Inputs/m-p/387204#M47163</guid>
      <dc:creator>Damien_Dallimor</dc:creator>
      <dc:date>2020-09-29T20:16:32Z</dc:date>
    </item>
  </channel>
</rss>

