<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Please help: I want to send data into Splunk Enterprise using API and I want to use Splunk HTTP Event collector in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Please-help-I-want-to-send-data-into-Splunk-Enterprise-using-API/m-p/527439#M88956</link>
    <description>Hi&lt;BR /&gt;This seem so be reasonable example. &lt;A href="https://github.com/jyung-hk/hec" target="_blank"&gt;https://github.com/jyung-hk/hec&lt;/A&gt;&lt;BR /&gt;You could find lot of other examples from net with google, if this is not suitable for you.&lt;BR /&gt;r. Ismo</description>
    <pubDate>Sun, 01 Nov 2020 09:48:38 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2020-11-01T09:48:38Z</dc:date>
    <item>
      <title>Please help: I want to send data into Splunk Enterprise using API and I want to use Splunk HTTP Event collector</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Please-help-I-want-to-send-data-into-Splunk-Enterprise-using-API/m-p/527436#M88955</link>
      <description>&lt;P&gt;Hello Folks,&lt;/P&gt;&lt;P&gt;I have data in JSON format (data.json). I want to visualize the data by creating a dashboard in Splunk Enterprise. Due to my company structure, I can only use the HTTP event collector (HEC) to send data to Splunk Enterprise. Can anyone please help me with the python based script if you have any template where I have to just enter the token key and URL to make it happen. Please help me as I need it on a quicker basis as it is super important for my project.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Nov 2020 06:36:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Please-help-I-want-to-send-data-into-Splunk-Enterprise-using-API/m-p/527436#M88955</guid>
      <dc:creator>jjoshi6</dc:creator>
      <dc:date>2020-11-01T06:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: Please help: I want to send data into Splunk Enterprise using API and I want to use Splunk HTTP Event collector</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Please-help-I-want-to-send-data-into-Splunk-Enterprise-using-API/m-p/527439#M88956</link>
      <description>Hi&lt;BR /&gt;This seem so be reasonable example. &lt;A href="https://github.com/jyung-hk/hec" target="_blank"&gt;https://github.com/jyung-hk/hec&lt;/A&gt;&lt;BR /&gt;You could find lot of other examples from net with google, if this is not suitable for you.&lt;BR /&gt;r. Ismo</description>
      <pubDate>Sun, 01 Nov 2020 09:48:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Please-help-I-want-to-send-data-into-Splunk-Enterprise-using-API/m-p/527439#M88956</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-11-01T09:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: Please help: I want to send data into Splunk Enterprise using API and I want to use Splunk HTTP Event collector</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Please-help-I-want-to-send-data-into-Splunk-Enterprise-using-API/m-p/527443#M88958</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228311"&gt;@jjoshi6&lt;/a&gt;&amp;nbsp;... hope you checked the github code and doing fine on your project work.&lt;/P&gt;&lt;P&gt;i assume you are new to Splunk. maybe i would like to suggest you...&lt;/P&gt;&lt;P&gt;1. play with a basic HEC data ingestion. once data from client reaches indexer, try to run SPL searches, try to create a basic dashboard on the HEC ingested data.&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. when you feel comfortable, then, as per your requirement, create some basic python template for HEC data onboarding.&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. when you are in doubt, reply us your current position in detail, then, someone can help on your task.&amp;nbsp;&lt;/P&gt;&lt;P&gt;4. For JSON format data, while searching, remember the command "spath"(field extraction on xml, json logs)(you dont need to write regular expressions for field extraction).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;~ Happy Splunking | Best Regards | Sekar | PS - Karma points appreciated!&lt;/P&gt;</description>
      <pubDate>Sun, 01 Nov 2020 13:03:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Please-help-I-want-to-send-data-into-Splunk-Enterprise-using-API/m-p/527443#M88958</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-11-01T13:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: Please help: I want to send data into Splunk Enterprise using API and I want to use Splunk HTTP Event collector</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Please-help-I-want-to-send-data-into-Splunk-Enterprise-using-API/m-p/528246#M89064</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80737"&gt;@inventsekar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 01:41:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Please-help-I-want-to-send-data-into-Splunk-Enterprise-using-API/m-p/528246#M89064</guid>
      <dc:creator>jjoshi6</dc:creator>
      <dc:date>2020-11-06T01:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: Please help: I want to send data into Splunk Enterprise using API and I want to use Splunk HTTP Event collector</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Please-help-I-want-to-send-data-into-Splunk-Enterprise-using-API/m-p/528250#M89065</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228311" target="_blank"&gt;@jjoshi6&lt;/A&gt;&amp;nbsp;.. you seems to be newbie to both python and splunk.. so its a big task i would say to a newbie.&amp;nbsp;&lt;/P&gt;&lt;P&gt;so, lets do this step by step...&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. have you configured data ingestion from a UF to indexer?&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. have you configured some "scripted inputs" from a UF to indexer?&lt;/P&gt;&lt;P&gt;3. have you configured a basic HEC data input to indexer..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;once you done these you will feel more comfortable and then you can check the github page which&amp;nbsp;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957" target="_blank"&gt;@richgalloway&lt;/A&gt;&amp;nbsp; (on the other post)and &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;given. hope its clear, all the best to your splunk and python journey!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a new member, you may not know about karma points,.. karma points will show your appreciation. thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 01:50:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Please-help-I-want-to-send-data-into-Splunk-Enterprise-using-API/m-p/528250#M89065</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-11-06T01:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: Please help: I want to send data into Splunk Enterprise using API and I want to use Splunk HTTP Event collector</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Please-help-I-want-to-send-data-into-Splunk-Enterprise-using-API/m-p/528251#M89066</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80737"&gt;@inventsekar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For all these three questions. I would say NO because I tried to send pseudo using CURL and it worked.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 02:00:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Please-help-I-want-to-send-data-into-Splunk-Enterprise-using-API/m-p/528251#M89066</guid>
      <dc:creator>jjoshi6</dc:creator>
      <dc:date>2020-11-06T02:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Please help: I want to send data into Splunk Enterprise using API and I want to use Splunk HTTP Event collector</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Please-help-I-want-to-send-data-into-Splunk-Enterprise-using-API/m-p/528252#M89067</link>
      <description>&lt;P&gt;ok sure, have you tried the "scripted input" method of "getting data in"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.0/AdvancedDev/ScriptedInputsIntro" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.0/AdvancedDev/ScriptedInputsIntro&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 02:02:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Please-help-I-want-to-send-data-into-Splunk-Enterprise-using-API/m-p/528252#M89067</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-11-06T02:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: Please help: I want to send data into Splunk Enterprise using API and I want to use Splunk HTTP Event collector</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Please-help-I-want-to-send-data-into-Splunk-Enterprise-using-API/m-p/528254#M89068</link>
      <description>&lt;P&gt;The permissions that I have for accessing splunk in my company does not allow me to Add Data. That's why I requested you to help me in writing Python Script.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80737"&gt;@inventsekar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 02:13:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Please-help-I-want-to-send-data-into-Splunk-Enterprise-using-API/m-p/528254#M89068</guid>
      <dc:creator>jjoshi6</dc:creator>
      <dc:date>2020-11-06T02:13:47Z</dc:date>
    </item>
  </channel>
</rss>

