All Apps and Add-ons

Are there an free App Api for splunk?

jotaforense
Explorer

Please indicate an application available in the splunk store (Find more Apps), preferably free. What possibility to establish authentication to an api type bearer?

I installed the "REST API Modular Input" app, but the activation key needs to be purchased.

Labels (1)
Tags (3)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

Are you looking to talk to Splunk's REST API, or do something else?  You do not need an app to use bearer type authentication with Splunk REST API.

0 Karma

jotaforense
Explorer

I want to export data from an api into my splunk, and for that I use an application, because I don't have access to the root user, I want to do it via applications.

0 Karma

yuanliu
SplunkTrust
SplunkTrust

By "an api" I assume you mean an api of a custom application in your organization.  There is no generic solution for such a use case.  But it is relatively simple to send data to Splunk's HTTP Event Collector (HEC).  See Get data with HTTP Event Collector.  You can also Get data from APIs and other remote data interfaces through scripted inputs.

There is another endpoint /services/receivers/simple that I sometimes use.  I'm pretty sure it used to be in an example, but I cannot find the document.  HEC and receivers endpoints all use bearer authentication, but HEC tokens are managed under "Data Inputs -> HEC", while general REST API tokens are managed under "Users and Authentication -> Authentication Methods".

0 Karma

jotaforense
Explorer

Hello @yuanliu , in my case I'm using the "REST API Modular Input" app - (pint attached), this app requires me to have a paid activation key, my api is a standard api with "bearer" authentication method.
REST API Modular Input.png
My question is if in addition to the "REST API Modular Input" there is another app that does the same function so that it does not require the activation key? did you understand?

0 Karma

yuanliu
SplunkTrust
SplunkTrust

Yes, I understand that REST API Modular Input app does not meet all your need.  The question is: What do you want to achieve with this app?  To me, the end goal of using this app is quite basic: To pull data from one or more of applications outside Splunk.  My other question is: Are these your own application, or a third-party application?

Regardless, as long as you have documentation of the applications API, any of the alternatives I suggested could achieve the same end goal, some requiring more additional coding than others.  @isoutamo's suggestion may save you even more coding.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

you could build your own TA for this. It’s quite simple with Splunk Add-on builder app https://splunkbase.splunk.com/app/2962

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...