All Apps and Add-ons

How to accept batch input from JSON REST API modular input?

dhruvgargTA
New Member

I have an endpoint that displays json data and I am looking for the REST polling data source to take native json lists and parse that as batch event input into Splunk.

Any Ideas?

0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

Use a custom response handler with the REST Modular Input that will can split up the batch json response into individual events .

You declare the name of the response handler in your REST setup screen.

You place the implementation of the response handler in rest_ta/bin/responsehandlers.py

Ships with loads of examples to refer to and copy.

View solution in original post

0 Karma

Damien_Dallimor
Ultra Champion

Use a custom response handler with the REST Modular Input that will can split up the batch json response into individual events .

You declare the name of the response handler in your REST setup screen.

You place the implementation of the response handler in rest_ta/bin/responsehandlers.py

Ships with loads of examples to refer to and copy.

0 Karma

dhruvgargTA
New Member

Hmm, after investigating the response handlers in the file, there's a default JSONArrayHandler that solves my problem perfectly. No custom code necessary.

Thanks.

0 Karma
Get Updates on the Splunk Community!

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...

Raise Your Skills at the .conf25 Builder Bar: Your Splunk Developer Destination

Calling all Splunk developers, custom SPL builders, dashboarders, and Splunkbase app creators – the Builder ...

Hunt Smarter, Not Harder: Discover New SPL “Recipes” in Our Threat Hunting Webinar

Are you ready to take your threat hunting skills to the next level? As Splunk community members, you know the ...