All Apps and Add-ons

How to accept batch input from JSON REST API modular input?

dhruvgargTA
New Member

I have an endpoint that displays json data and I am looking for the REST polling data source to take native json lists and parse that as batch event input into Splunk.

Any Ideas?

0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

Use a custom response handler with the REST Modular Input that will can split up the batch json response into individual events .

You declare the name of the response handler in your REST setup screen.

You place the implementation of the response handler in rest_ta/bin/responsehandlers.py

Ships with loads of examples to refer to and copy.

View solution in original post

0 Karma

Damien_Dallimor
Ultra Champion

Use a custom response handler with the REST Modular Input that will can split up the batch json response into individual events .

You declare the name of the response handler in your REST setup screen.

You place the implementation of the response handler in rest_ta/bin/responsehandlers.py

Ships with loads of examples to refer to and copy.

0 Karma

dhruvgargTA
New Member

Hmm, after investigating the response handlers in the file, there's a default JSONArrayHandler that solves my problem perfectly. No custom code necessary.

Thanks.

0 Karma
Get Updates on the Splunk Community!

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...