<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: REST Inputs in cluster architecture in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/REST-Inputs-in-cluster-architecture/m-p/275961#M52944</link>
    <description>&lt;P&gt;Figured this one out. As stated in &lt;A href="http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings"&gt;http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings&lt;/A&gt;, REST TA app needs to be installed on all HeavyForwarders - and the deployment-app should be used in HeavyForwarder configuration.&lt;/P&gt;</description>
    <pubDate>Fri, 10 Mar 2017 06:03:25 GMT</pubDate>
    <dc:creator>mudragada</dc:creator>
    <dc:date>2017-03-10T06:03:25Z</dc:date>
    <item>
      <title>REST Inputs in cluster architecture</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/REST-Inputs-in-cluster-architecture/m-p/275955#M52938</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a Splunk Heavy Forwarder, Indexer master and two Indexer slaves, two search heads in the current architecture.&lt;BR /&gt;
I have few rest inputs within the network (a firewall away) to get the values in.&lt;/P&gt;

&lt;P&gt;Now, I need to choose the machine on which the rest_ta app can be installed and define the rest inputs, to an existing index.&lt;/P&gt;

&lt;P&gt;By practice/convention, where should the rest_ta app be installed and the inputs defined?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 04:57:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/REST-Inputs-in-cluster-architecture/m-p/275955#M52938</guid>
      <dc:creator>mudragada</dc:creator>
      <dc:date>2017-02-03T04:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: REST Inputs in cluster architecture</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/REST-Inputs-in-cluster-architecture/m-p/275956#M52939</link>
      <description>&lt;P&gt;Hi mudragada, &lt;BR /&gt;
the Heavy Forwarder is probably your best bet here. the inputs will be defined from the GUI - settings (top right corner) -&amp;gt; Data inputs -&amp;gt; REST&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2017 16:46:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/REST-Inputs-in-cluster-architecture/m-p/275956#M52939</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-02-24T16:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: REST Inputs in cluster architecture</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/REST-Inputs-in-cluster-architecture/m-p/275957#M52940</link>
      <description>&lt;P&gt;I have about 700 rest inputs - which I need to define in a conf file. When I did via the UI, they're going into apps/search/local/inputs.conf. Is there a way we can define the inputs in a different file or folder, other than the ones that are defined already in the search app? &lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2017 04:22:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/REST-Inputs-in-cluster-architecture/m-p/275957#M52940</guid>
      <dc:creator>mudragada</dc:creator>
      <dc:date>2017-03-01T04:22:13Z</dc:date>
    </item>
    <item>
      <title>Re: REST Inputs in cluster architecture</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/REST-Inputs-in-cluster-architecture/m-p/275958#M52941</link>
      <description>&lt;P&gt;there are many rest inputs packaged ni prebuilt apps, AWS and SalesForce are just an example link here: &lt;A href="https://splunkbase.splunk.com/app/1274/"&gt;https://splunkbase.splunk.com/app/1274/&lt;/A&gt; and are free to download at splunkbase.  you can package rest inputs in apps of your choice. &lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2017 14:40:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/REST-Inputs-in-cluster-architecture/m-p/275958#M52941</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-03-01T14:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: REST Inputs in cluster architecture</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/REST-Inputs-in-cluster-architecture/m-p/275959#M52942</link>
      <description>&lt;P&gt;The REST end points are internal to my network and REST Modular input is what I chose to enable them in Splunk to gather data. AWS app or SalesForce app may not help the situation.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2017 15:34:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/REST-Inputs-in-cluster-architecture/m-p/275959#M52942</guid>
      <dc:creator>mudragada</dc:creator>
      <dc:date>2017-03-01T15:34:49Z</dc:date>
    </item>
    <item>
      <title>Re: REST Inputs in cluster architecture</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/REST-Inputs-in-cluster-architecture/m-p/275960#M52943</link>
      <description>&lt;P&gt;sure, it was just an example, so you can follow the inputs structure.&lt;BR /&gt;
to your question, yes you can configure in different apps, therefore separate folder&lt;BR /&gt;
hope it helps&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2017 15:38:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/REST-Inputs-in-cluster-architecture/m-p/275960#M52943</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-03-01T15:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: REST Inputs in cluster architecture</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/REST-Inputs-in-cluster-architecture/m-p/275961#M52944</link>
      <description>&lt;P&gt;Figured this one out. As stated in &lt;A href="http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings"&gt;http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings&lt;/A&gt;, REST TA app needs to be installed on all HeavyForwarders - and the deployment-app should be used in HeavyForwarder configuration.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 06:03:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/REST-Inputs-in-cluster-architecture/m-p/275961#M52944</guid>
      <dc:creator>mudragada</dc:creator>
      <dc:date>2017-03-10T06:03:25Z</dc:date>
    </item>
  </channel>
</rss>

