<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: forwarding to third party REST endpoint in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/forwarding-to-third-party-REST-endpoint/m-p/557466#M18937</link>
    <description>&lt;P&gt;Thanks for the help&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163730"&gt;@venkatasri&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Jun 2021 20:27:35 GMT</pubDate>
    <dc:creator>vijay</dc:creator>
    <dc:date>2021-06-28T20:27:35Z</dc:date>
    <item>
      <title>forwarding to third party REST endpoint</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/forwarding-to-third-party-REST-endpoint/m-p/557295#M18933</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Is it possible&amp;nbsp; from Splunk universal/heavy forwarder to forward data to third party REST API endpoint over https using basic authentication ?&lt;/P&gt;&lt;P&gt;I have use case where&amp;nbsp;Splunk universal/heavy forwarder has to forward data to&amp;nbsp;Splunk enterprise + 3rd party client REST api endpoint for processing data.&lt;/P&gt;&lt;P&gt;Is this use case possible ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Jun 2021 14:53:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/forwarding-to-third-party-REST-endpoint/m-p/557295#M18933</guid>
      <dc:creator>vijay</dc:creator>
      <dc:date>2021-06-27T14:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding to third party REST endpoint</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/forwarding-to-third-party-REST-endpoint/m-p/557315#M18934</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235838"&gt;@vijay&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Splunk docs suggest HF can forward to only TCP endpoint not to HTTP Rest API. You can find same documentation here -&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd" target="_blank" rel="noopener"&gt;Forward data to third-party systems - Splunk Documentation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you wish to do so i would do using store-and-forward model using custom script.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Receive on HF and store the data to a file&lt;/LI&gt;&lt;LI&gt;write a custom script to read every line from a file and curl to Rest API either line-by-line or batch mode.&lt;/LI&gt;&lt;LI&gt;You can cron schedule the script to run and have a checkpoint to track where you have last read the stored file... and retry in case of target Rest API failed to receive.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;An upvote would be appreciated &amp;amp; Accept solution if it helps!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 00:25:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/forwarding-to-third-party-REST-endpoint/m-p/557315#M18934</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-06-28T00:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding to third party REST endpoint</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/forwarding-to-third-party-REST-endpoint/m-p/557466#M18937</link>
      <description>&lt;P&gt;Thanks for the help&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163730"&gt;@venkatasri&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 20:27:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/forwarding-to-third-party-REST-endpoint/m-p/557466#M18937</guid>
      <dc:creator>vijay</dc:creator>
      <dc:date>2021-06-28T20:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding to third party REST endpoint</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/forwarding-to-third-party-REST-endpoint/m-p/557471#M18938</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235838"&gt;@vijay&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to correct first bullet point about custom setup, you can not enforce HF to store data on file it can only index the data. Hence you have to implement script on the machine where originally present. Hope it helps Appreciate if you could Accept the solution.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 21:46:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/forwarding-to-third-party-REST-endpoint/m-p/557471#M18938</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-06-28T21:46:10Z</dc:date>
    </item>
  </channel>
</rss>

