<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need a help with posting data using Rest API's from one Splunk to another in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Need-a-help-with-posting-data-using-Rest-API-s-from-one-Splunk/m-p/399972#M71222</link>
    <description>&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/345295/wrap-a-webhook-for-use-with-http-event-collector.html"&gt;https://answers.splunk.com/answers/345295/wrap-a-webhook-for-use-with-http-event-collector.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Jul 2019 16:33:59 GMT</pubDate>
    <dc:creator>jkat54</dc:creator>
    <dc:date>2019-07-18T16:33:59Z</dc:date>
    <item>
      <title>Need a help with posting data using Rest API's from one Splunk to another</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-a-help-with-posting-data-using-Rest-API-s-from-one-Splunk/m-p/399966#M71216</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;I have my own Splunk where I installed SPLUNK ES &lt;BR /&gt;
and I just got the Search head access from somebody's SPLUNK where I can Create alerts ( no backend Access). Just to see data and create Knowledge objects. &lt;/P&gt;

&lt;P&gt;I want to create an alert is 3rd party Splunk and in alert actions I want to use WEBHOOK action and need to give the Splunk rest API to post the alert data into my Search head where I installed ES as a notable events.&lt;/P&gt;

&lt;P&gt;how should I post the alert data using rest api from 3rd party Splunk where I got the only UI access to my SPLUNK ES?&lt;BR /&gt;
how to create an Index using rest API post ?&lt;/P&gt;

&lt;P&gt;Thanks in advance..any help would be appreciated..&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2019 01:53:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-a-help-with-posting-data-using-Rest-API-s-from-one-Splunk/m-p/399966#M71216</guid>
      <dc:creator>satyaallaparthi</dc:creator>
      <dc:date>2019-07-18T01:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help with posting data using Rest API's from one Splunk to another</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-a-help-with-posting-data-using-Rest-API-s-from-one-Splunk/m-p/399967#M71217</link>
      <description>&lt;P&gt;Ok to help clarify...&lt;/P&gt;

&lt;P&gt;You want to use webhook to post a notable to ES from another search head that is not ES.&lt;/P&gt;

&lt;P&gt;You also do not have admin access on the non-ES SH.&lt;/P&gt;

&lt;P&gt;Is this correct?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2019 11:55:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-a-help-with-posting-data-using-Rest-API-s-from-one-Splunk/m-p/399967#M71217</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2019-07-18T11:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help with posting data using Rest API's from one Splunk to another</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-a-help-with-posting-data-using-Rest-API-s-from-one-Splunk/m-p/399968#M71218</link>
      <description>&lt;P&gt;Have a search that finds what you want to send and send it to the other instance via HEC for indexing.Then you can further search and alert or make notables in the receiving instance.  A working TA you can use or rip apart and do your own.&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/3508/"&gt;https://splunkbase.splunk.com/app/3508/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2019 14:55:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-a-help-with-posting-data-using-Rest-API-s-from-one-Splunk/m-p/399968#M71218</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2019-07-18T14:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help with posting data using Rest API's from one Splunk to another</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-a-help-with-posting-data-using-Rest-API-s-from-one-Splunk/m-p/399969#M71219</link>
      <description>&lt;P&gt;Can you please explain me little clear..  &lt;/P&gt;

&lt;P&gt;I really don't know what permissions I will get for that Instance.. might be only Power user where I can just create an alert..  but not the permission to install apps cause that is in our cyber defense center. &lt;/P&gt;

&lt;P&gt;That is the reason why I want to post via splunk rest where I can keep that in webhook alert action.&lt;/P&gt;

&lt;P&gt;Can I do that ?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2019 15:14:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-a-help-with-posting-data-using-Rest-API-s-from-one-Splunk/m-p/399969#M71219</guid>
      <dc:creator>satyaallaparthi</dc:creator>
      <dc:date>2019-07-18T15:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help with posting data using Rest API's from one Splunk to another</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-a-help-with-posting-data-using-Rest-API-s-from-one-Splunk/m-p/399970#M71220</link>
      <description>&lt;P&gt;Yes, You are absolutely correct.. I will have the permissions to create an alert actions where I want to keep splunk rest in webhook.&lt;/P&gt;

&lt;P&gt;Thanks, &lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2019 15:26:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-a-help-with-posting-data-using-Rest-API-s-from-one-Splunk/m-p/399970#M71220</guid>
      <dc:creator>satyaallaparthi</dc:creator>
      <dc:date>2019-07-18T15:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help with posting data using Rest API's from one Splunk to another</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-a-help-with-posting-data-using-Rest-API-s-from-one-Splunk/m-p/399971#M71221</link>
      <description>&lt;P&gt;He's saying that you setup HEC on a splunk instance, and use the webhook feature to post to the HEC.  You will control the HEC on your end.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2019 16:33:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-a-help-with-posting-data-using-Rest-API-s-from-one-Splunk/m-p/399971#M71221</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2019-07-18T16:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help with posting data using Rest API's from one Splunk to another</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-a-help-with-posting-data-using-Rest-API-s-from-one-Splunk/m-p/399972#M71222</link>
      <description>&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/345295/wrap-a-webhook-for-use-with-http-event-collector.html"&gt;https://answers.splunk.com/answers/345295/wrap-a-webhook-for-use-with-http-event-collector.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2019 16:33:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-a-help-with-posting-data-using-Rest-API-s-from-one-Splunk/m-p/399972#M71222</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2019-07-18T16:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help with posting data using Rest API's from one Splunk to another</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-a-help-with-posting-data-using-Rest-API-s-from-one-Splunk/m-p/399973#M71223</link>
      <description>&lt;P&gt;But unfortunately, that is not my criteria.. I want to create alert as a notable event in my ES via via splunk rest end points..&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 12:52:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-a-help-with-posting-data-using-Rest-API-s-from-one-Splunk/m-p/399973#M71223</guid>
      <dc:creator>satyaallaparthi</dc:creator>
      <dc:date>2019-07-19T12:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help with posting data using Rest API's from one Splunk to another</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-a-help-with-posting-data-using-Rest-API-s-from-one-Splunk/m-p/399974#M71224</link>
      <description>&lt;P&gt;But unfortunately, that is not my criteria.. I want to create, alert as a notable event in my ES via splunk rest end points..and I want to know what is the rest end that I can use in webhook. &lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 12:54:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-a-help-with-posting-data-using-Rest-API-s-from-one-Splunk/m-p/399974#M71224</guid>
      <dc:creator>satyaallaparthi</dc:creator>
      <dc:date>2019-07-19T12:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: Need a help with posting data using Rest API's from one Splunk to another</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-a-help-with-posting-data-using-Rest-API-s-from-one-Splunk/m-p/399975#M71225</link>
      <description>&lt;P&gt;how to add the rest in webhook using HEC...what rest I should add ?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 15:15:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-a-help-with-posting-data-using-Rest-API-s-from-one-Splunk/m-p/399975#M71225</guid>
      <dc:creator>satyaallaparthi</dc:creator>
      <dc:date>2019-07-19T15:15:41Z</dc:date>
    </item>
  </channel>
</rss>

