<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trigger HTTP call for every event received at Real time in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Trigger-HTTP-call-for-every-event-received-at-Real-time/m-p/184736#M36989</link>
    <description>&lt;P&gt;Hi thebosshere,&lt;/P&gt;

&lt;P&gt;regarding the first part of your use case, this is no problem in Splunk. You can either setup &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/Aboutindexedfieldextraction"&gt;index time field extraction&lt;/A&gt; or &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Knowledge/Addfieldsatsearchtime"&gt;search time field extraction&lt;/A&gt; to get your needed fields.&lt;/P&gt;

&lt;P&gt;The next part of your use case could be tricky; because this is not really Splunk related, but a question of how this remote HTTP call should be triggered on the remote system. &lt;/P&gt;

&lt;P&gt;You can setup a real-time alert, which searches for your events and fires a script on every match.&lt;/P&gt;

&lt;P&gt;Maybe this can be of help for you: &lt;A href="http://wiki.splunk.com/Community:Use_Splunk_alerts_with_scripts_to_create_a_ticket_in_your_ticketing_system"&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/A&gt;&lt;A href="http://wiki.splunk.com/Community:Use_Splunk_alerts_with_scripts_to_create_a_ticket_in_your_ticketing_system" target="test_blank"&gt;http://wiki.splunk.com/Community:Use_Splunk_alerts_with_scripts_to_create_a_ticket_in_your_ticketing_system&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
    <pubDate>Mon, 18 Aug 2014 08:16:13 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2014-08-18T08:16:13Z</dc:date>
    <item>
      <title>Trigger HTTP call for every event received at Real time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trigger-HTTP-call-for-every-event-received-at-Real-time/m-p/184735#M36988</link>
      <description>&lt;P&gt;I have an use case in which for every event/data-input that reaches the Splunk server, certain fields need to be parsed out and a HTTP call triggered with the parsed parameters in the real-time non-window'd mode. What is the appropriate way to achieve that.&lt;/P&gt;

&lt;P&gt;Splunk Version used: 6.x&lt;/P&gt;

&lt;P&gt;Thanks in Advance.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Aug 2014 20:18:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trigger-HTTP-call-for-every-event-received-at-Real-time/m-p/184735#M36988</guid>
      <dc:creator>thebosshere</dc:creator>
      <dc:date>2014-08-16T20:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger HTTP call for every event received at Real time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trigger-HTTP-call-for-every-event-received-at-Real-time/m-p/184736#M36989</link>
      <description>&lt;P&gt;Hi thebosshere,&lt;/P&gt;

&lt;P&gt;regarding the first part of your use case, this is no problem in Splunk. You can either setup &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/Aboutindexedfieldextraction"&gt;index time field extraction&lt;/A&gt; or &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Knowledge/Addfieldsatsearchtime"&gt;search time field extraction&lt;/A&gt; to get your needed fields.&lt;/P&gt;

&lt;P&gt;The next part of your use case could be tricky; because this is not really Splunk related, but a question of how this remote HTTP call should be triggered on the remote system. &lt;/P&gt;

&lt;P&gt;You can setup a real-time alert, which searches for your events and fires a script on every match.&lt;/P&gt;

&lt;P&gt;Maybe this can be of help for you: &lt;A href="http://wiki.splunk.com/Community:Use_Splunk_alerts_with_scripts_to_create_a_ticket_in_your_ticketing_system"&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/A&gt;&lt;A href="http://wiki.splunk.com/Community:Use_Splunk_alerts_with_scripts_to_create_a_ticket_in_your_ticketing_system" target="test_blank"&gt;http://wiki.splunk.com/Community:Use_Splunk_alerts_with_scripts_to_create_a_ticket_in_your_ticketing_system&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2014 08:16:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trigger-HTTP-call-for-every-event-received-at-Real-time/m-p/184736#M36989</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-08-18T08:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger HTTP call for every event received at Real time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trigger-HTTP-call-for-every-event-received-at-Real-time/m-p/184737#M36990</link>
      <description>&lt;P&gt;Thanks MuS. When I go through the wiki link, it mentions "saved search". Does this mean the Real time stream cant be accessed directly by the script? Newbie to this area, so my doubts may be completely wrong.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2014 09:38:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trigger-HTTP-call-for-every-event-received-at-Real-time/m-p/184737#M36990</guid>
      <dc:creator>thebosshere</dc:creator>
      <dc:date>2014-08-18T09:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger HTTP call for every event received at Real time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trigger-HTTP-call-for-every-event-received-at-Real-time/m-p/184738#M36991</link>
      <description>&lt;P&gt;take the wiki link as example not as solution for your use case &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; Just create a real-time alert that fires a script each time it gets a hit on your events. What that script should do is up to the remote / receiving system....&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2014 10:13:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trigger-HTTP-call-for-every-event-received-at-Real-time/m-p/184738#M36991</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-08-18T10:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: Trigger HTTP call for every event received at Real time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trigger-HTTP-call-for-every-event-received-at-Real-time/m-p/184739#M36992</link>
      <description>&lt;P&gt;Thanks MuS. Yes used your suggestion as starting point. That helped.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2014 12:22:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trigger-HTTP-call-for-every-event-received-at-Real-time/m-p/184739#M36992</guid>
      <dc:creator>thebosshere</dc:creator>
      <dc:date>2014-08-18T12:22:56Z</dc:date>
    </item>
  </channel>
</rss>

