<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to connect the SEP api using python? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-connect-the-SEP-api-using-python/m-p/592356#M10714</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;BR /&gt;I am trying to connect the SEP api via python and my code is as follows -&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;# encoding = utf-8&lt;/P&gt;
&lt;P&gt;import os&lt;BR /&gt;import sys&lt;BR /&gt;import time&lt;BR /&gt;import datetime&lt;BR /&gt;import json&lt;BR /&gt;import requests&lt;/P&gt;
&lt;P&gt;import base64&lt;/P&gt;
&lt;P&gt;'''&lt;BR /&gt;IMPORTANT&lt;BR /&gt;Edit only the validate_input and collect_events functions.&lt;BR /&gt;Do not edit any other part in this file.&lt;BR /&gt;This file is generated only once when creating the modular input.&lt;BR /&gt;'''&lt;BR /&gt;'''&lt;BR /&gt;# For advanced users, if you want to create single instance mod input, uncomment this method.&lt;BR /&gt;def use_single_instance_mode():&lt;BR /&gt;return True&lt;BR /&gt;'''&lt;/P&gt;
&lt;P&gt;def validate_input(helper, definition):&lt;BR /&gt;"""Implement your own validation logic to validate the input stanza configurations"""&lt;BR /&gt;# This example accesses the modular input variable&lt;BR /&gt;# text = definition.parameters.get('text', None)&lt;BR /&gt;# text_1 = definition.parameters.get('text_1', None)&lt;BR /&gt;pass&lt;/P&gt;
&lt;P&gt;def collect_events(helper, ew):&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;opt_clientid = helper.get_arg('clientid')&lt;BR /&gt;&amp;nbsp;opt_clientsecret = helper.get_arg('clientsecret')&lt;BR /&gt;&amp;nbsp;opt_customerid = helper.get_arg('customerid')&lt;BR /&gt;&amp;nbsp;opt_domainid = helper.get_arg('domainid')&lt;BR /&gt;&amp;nbsp;opt_apihost = helper.get_arg('apihost')&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;tokenUrl = "https://" + opt_apihost + "/v1/oauth2/tokens"&lt;BR /&gt;&amp;nbsp;post = []&lt;BR /&gt;files = []&lt;/P&gt;
&lt;P&gt;s = requests.Session()&lt;BR /&gt;e = (opt_clientid + ':' + opt_clientsecret)&lt;BR /&gt;en = e.encode('utf-8')&lt;BR /&gt;en64 = base64.urlsafe_b64encode(en)&lt;BR /&gt;s.headers.update({ 'Accept': 'application/json' })&lt;BR /&gt;s.headers.update({ 'Authorization': 'Basic ' + str(en64.decode()) })&lt;BR /&gt;s.headers.update({ 'Content-Type': 'application/x-www-form-urlencoded' })&lt;BR /&gt;s.headers.update({ 'Host': opt_apihost })&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;f = s.post(tokenUrl, data=post, files=files, verify=False)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;r = json.loads(f.text)&lt;BR /&gt;access_token = r['access_token']&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;url = "https://" + opt_apihost + "/v1/devices"&lt;BR /&gt;parameters = {"authorization":access_token}&lt;BR /&gt;final_result = []&lt;BR /&gt;# The following examples send rest requests to some endpoint.&lt;BR /&gt;response = helper.send_http_request(url, 'GET', parameters=None, payload=None,headers=parameters, cookies=None, verify=True, cert=None,timeout=None, use_proxy=True)&lt;BR /&gt;# get the response headers&lt;BR /&gt;#r_headers = response.headers&lt;BR /&gt;# get the response body as text&lt;BR /&gt;#r_text = response.text&lt;BR /&gt;# get response body as json. If the body text is not a json string, raise a ValueError&lt;BR /&gt;r_json = response.json()&lt;BR /&gt;for devices in r_json["devices"]:&lt;BR /&gt;state = helper.get_check_point(str(devices["id"]))&lt;BR /&gt;if state is None:&lt;BR /&gt;final_result.append(devices)&lt;BR /&gt;helper.save_check_point(str(devices["id"]), "Indexed")&lt;BR /&gt;event = helper.new_event(json.dumps(final_result), time=None, host=None, index=None, source=None, sourcetype=None, done=True, unbroken=False)&lt;BR /&gt;ew.write_event(event)&lt;/P&gt;
&lt;P&gt;The test code works fine, but&lt;/P&gt;
&lt;P&gt;1. The events are being indexed, each value is not appearing as a seperate entity but is rather grouped&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. The data is not being updated in the interval mentioned in the beginning&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Apr 2022 15:37:49 GMT</pubDate>
    <dc:creator>SumukhVenugopal</dc:creator>
    <dc:date>2022-04-05T15:37:49Z</dc:date>
    <item>
      <title>How to connect the SEP api using python?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-connect-the-SEP-api-using-python/m-p/592356#M10714</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;BR /&gt;I am trying to connect the SEP api via python and my code is as follows -&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;# encoding = utf-8&lt;/P&gt;
&lt;P&gt;import os&lt;BR /&gt;import sys&lt;BR /&gt;import time&lt;BR /&gt;import datetime&lt;BR /&gt;import json&lt;BR /&gt;import requests&lt;/P&gt;
&lt;P&gt;import base64&lt;/P&gt;
&lt;P&gt;'''&lt;BR /&gt;IMPORTANT&lt;BR /&gt;Edit only the validate_input and collect_events functions.&lt;BR /&gt;Do not edit any other part in this file.&lt;BR /&gt;This file is generated only once when creating the modular input.&lt;BR /&gt;'''&lt;BR /&gt;'''&lt;BR /&gt;# For advanced users, if you want to create single instance mod input, uncomment this method.&lt;BR /&gt;def use_single_instance_mode():&lt;BR /&gt;return True&lt;BR /&gt;'''&lt;/P&gt;
&lt;P&gt;def validate_input(helper, definition):&lt;BR /&gt;"""Implement your own validation logic to validate the input stanza configurations"""&lt;BR /&gt;# This example accesses the modular input variable&lt;BR /&gt;# text = definition.parameters.get('text', None)&lt;BR /&gt;# text_1 = definition.parameters.get('text_1', None)&lt;BR /&gt;pass&lt;/P&gt;
&lt;P&gt;def collect_events(helper, ew):&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;opt_clientid = helper.get_arg('clientid')&lt;BR /&gt;&amp;nbsp;opt_clientsecret = helper.get_arg('clientsecret')&lt;BR /&gt;&amp;nbsp;opt_customerid = helper.get_arg('customerid')&lt;BR /&gt;&amp;nbsp;opt_domainid = helper.get_arg('domainid')&lt;BR /&gt;&amp;nbsp;opt_apihost = helper.get_arg('apihost')&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;tokenUrl = "https://" + opt_apihost + "/v1/oauth2/tokens"&lt;BR /&gt;&amp;nbsp;post = []&lt;BR /&gt;files = []&lt;/P&gt;
&lt;P&gt;s = requests.Session()&lt;BR /&gt;e = (opt_clientid + ':' + opt_clientsecret)&lt;BR /&gt;en = e.encode('utf-8')&lt;BR /&gt;en64 = base64.urlsafe_b64encode(en)&lt;BR /&gt;s.headers.update({ 'Accept': 'application/json' })&lt;BR /&gt;s.headers.update({ 'Authorization': 'Basic ' + str(en64.decode()) })&lt;BR /&gt;s.headers.update({ 'Content-Type': 'application/x-www-form-urlencoded' })&lt;BR /&gt;s.headers.update({ 'Host': opt_apihost })&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;f = s.post(tokenUrl, data=post, files=files, verify=False)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;r = json.loads(f.text)&lt;BR /&gt;access_token = r['access_token']&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;url = "https://" + opt_apihost + "/v1/devices"&lt;BR /&gt;parameters = {"authorization":access_token}&lt;BR /&gt;final_result = []&lt;BR /&gt;# The following examples send rest requests to some endpoint.&lt;BR /&gt;response = helper.send_http_request(url, 'GET', parameters=None, payload=None,headers=parameters, cookies=None, verify=True, cert=None,timeout=None, use_proxy=True)&lt;BR /&gt;# get the response headers&lt;BR /&gt;#r_headers = response.headers&lt;BR /&gt;# get the response body as text&lt;BR /&gt;#r_text = response.text&lt;BR /&gt;# get response body as json. If the body text is not a json string, raise a ValueError&lt;BR /&gt;r_json = response.json()&lt;BR /&gt;for devices in r_json["devices"]:&lt;BR /&gt;state = helper.get_check_point(str(devices["id"]))&lt;BR /&gt;if state is None:&lt;BR /&gt;final_result.append(devices)&lt;BR /&gt;helper.save_check_point(str(devices["id"]), "Indexed")&lt;BR /&gt;event = helper.new_event(json.dumps(final_result), time=None, host=None, index=None, source=None, sourcetype=None, done=True, unbroken=False)&lt;BR /&gt;ew.write_event(event)&lt;/P&gt;
&lt;P&gt;The test code works fine, but&lt;/P&gt;
&lt;P&gt;1. The events are being indexed, each value is not appearing as a seperate entity but is rather grouped&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. The data is not being updated in the interval mentioned in the beginning&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 15:37:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-connect-the-SEP-api-using-python/m-p/592356#M10714</guid>
      <dc:creator>SumukhVenugopal</dc:creator>
      <dc:date>2022-04-05T15:37:49Z</dc:date>
    </item>
  </channel>
</rss>

