<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pulling data into splunk via API in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Pulling-data-into-splunk-via-API/m-p/740863#M117768</link>
    <description>&lt;P&gt;Further to my last message - this is a great blog post on getting started with UCC so well worth checking out&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/blog/customers/managing-splunk-add-ons-with-ucc-framework.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/customers/managing-splunk-add-ons-with-ucc-framework.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Let us know how you get on and if you have any further questions &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
    <pubDate>Tue, 04 Mar 2025 22:42:32 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2025-03-04T22:42:32Z</dc:date>
    <item>
      <title>Pulling data into splunk via API</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Pulling-data-into-splunk-via-API/m-p/740832#M117763</link>
      <description>&lt;P&gt;What is the best practice to have a Splunk heavy forwarder call out to a third party API and pull logs into Splunk. Most of the solutions I use have apps on Splunk base but this one does not. Do I have to build a custom add-on using something like the &lt;A title="Splunk Add-On builder " href="https://splunkbase.splunk.com/app/2962" target="_self"&gt;add-on builder&lt;/A&gt;?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 19:48:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Pulling-data-into-splunk-via-API/m-p/740832#M117763</guid>
      <dc:creator>dolj</dc:creator>
      <dc:date>2025-03-04T19:48:04Z</dc:date>
    </item>
    <item>
      <title>Re: Pulling data into splunk via API</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Pulling-data-into-splunk-via-API/m-p/740862#M117767</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/61094"&gt;@dolj&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there isnt already a Splunkbase app for the API you want to work with then you may be best using the &lt;A href="https://splunk.github.io/addonfactory-ucc-generator/" target="_self"&gt;Splunk&amp;nbsp;&lt;/A&gt;&lt;SPAN&gt;&lt;A href="https://splunk.github.io/addonfactory-ucc-generator/" target="_self"&gt;Universal Configuration Console (UCC) framework&lt;/A&gt; to build yourself a custom app. This has had much more development recently than Add-on builder and is easier to manage moving forwards.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here is a sample app which might give some insight on how it works, this is taken from a Conf talk I did on creating a simple API app in 2023.&amp;nbsp;&lt;A href="https://github.com/livehybrid/conf23-dev1091b/" target="_blank"&gt;https://github.com/livehybrid/conf23-dev1091b/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also have a look at the UCC docs (&lt;A href="https://splunk.github.io/addonfactory-ucc-generator/" target="_blank"&gt;https://splunk.github.io/addonfactory-ucc-generator/&lt;/A&gt;) for more information and to get started.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 22:41:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Pulling-data-into-splunk-via-API/m-p/740862#M117767</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-04T22:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: Pulling data into splunk via API</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Pulling-data-into-splunk-via-API/m-p/740863#M117768</link>
      <description>&lt;P&gt;Further to my last message - this is a great blog post on getting started with UCC so well worth checking out&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/blog/customers/managing-splunk-add-ons-with-ucc-framework.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/customers/managing-splunk-add-ons-with-ucc-framework.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Let us know how you get on and if you have any further questions &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 22:42:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Pulling-data-into-splunk-via-API/m-p/740863#M117768</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-04T22:42:32Z</dc:date>
    </item>
  </channel>
</rss>

