All Apps and Add-ons

Configuration Metadata in Config from REST APIs?

StephanPCossett
Engager

Hello All,

Our client would like to be able to annotate their configuration stanzas with metadata about the ingestion (e.g. date of setup, business unit, application ID, person who did configuration, etc.) None of this data will actually used by Splunk, it's just us tagging data into the stanzas. So as an example, I have the following config stanza:

[monitor://C:\GitRepos\service-information-display-svc\logs]
disabled = false
index = localindex
sourcetype = _json
host = LALA_ONE

We'd like to do something like this via the API:

[monitor://C:\GitRepos\service-information-display-svc\logs]
disabled = false
index = localindex
sourcetype = _json
host = LALA_ONE
_createdby = scossette
_dateCreated = 07302018
_appId = 054838
_businessUnit = sales

When trying to add them through the APIs, it comes back as an HTTP 400... most likely because the parameter names are not supported via Splunk. Is this even possible? If so, how?

Thanks in Advance,
Steve

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...