Alerting

How to write API results made by splunk Alert action to a custom index

nareshkumarg
Path Finder

Hello all,

I have a requirement to forward events from a search result to an API and store the response from the API call made by an alert action back to a custom index. How can I achieve this. Please help.

Regards,

Naresh

Labels (2)
0 Karma
1 Solution

nareshkumarg
Path Finder

Looks like the only way is to use HEC method to make an API call back to store the data in to an index we want. Kind of a pain but this what I got from Splunk support. I wonder whether Splunk will add this feature OOB on its future version.

Regards,

Naresh

View solution in original post

0 Karma

nareshkumarg
Path Finder

Looks like the only way is to use HEC method to make an API call back to store the data in to an index we want. Kind of a pain but this what I got from Splunk support. I wonder whether Splunk will add this feature OOB on its future version.

Regards,

Naresh

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I think you've asked this question before.  I don't have experience with the SDK so I can't help in that area.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Sounds like you need a custom search command.  See https://docs.splunk.com/Documentation/Splunk/8.0.6/Search/Aboutcustomsearchcommands

---
If this reply helps you, Karma would be appreciated.
0 Karma

nareshkumarg
Path Finder

@richgalloway I have built an addon to create an alert action where My API call works. Once the call gets completed the API responds with a JSON data which I want to store on a custom index. Currently, it stores the data by default into the Main index which we don't want to use.

I used the following code using the Splunk add-on builder to write it but it writes the data into the Main index.

helper.addevent("hello", sourcetype="customsource")
helper.addevent("world", sourcetype="customsource")
helper.writeevents(index="mycustomindex", host="localhost", source="localhost")

How to proceed further.

0 Karma

AMAN0113
Explorer

Hi @nareshkumarg,

Did you find a solution to the above? If so, could you please let me know what you found?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...