All Apps and Add-ons

How to import data from vCloud Director into Splunk using API?

davide_talesco
New Member

Hi,

I am trying to get DATA into SPLUNK from my vcloud director environment.
I am using the REST API Modular Input app but I am always getting a HTTP Request error: 403 Client Error: Forbidden.
I am using basic authentication and with same details/credentials I am able to use curl or Mozilla RestClient to query vcloud director API succesful.

Has anyone had any experience in importing data from vcloud director into splunk using API?

Thanks,
Davide.

0 Karma

davide_talesco
New Member

Here you are:

[root@r2-prdcldnfs apps]# find . -name inputs.conf | xargs grep vcloud_rest
./launcher/local/inputs.conf:[rest://vcloud_rest]
[root@r2-prdcldnfs apps]# cat ./launcher/local/inputs.conf
[rest://vcloud_rest]
auth_password = Password
auth_type = basic
auth_user = sale1@Sales-LAB
endpoint = https://10.0.0.21/api/query
http_header_propertys = Accept=application/*+xml,version=1.5
http_method = GET
index_error_response_codes = 0
response_type = xml
streaming_request = 0
url_args = type=task,format=records
[root@r2-prdcldnfs apps]#

In /opt/splunk/var/log/splunk/splunkd.log I always get
10-28-2014 09:41:53.214 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/rest_ta/bin/rest.py" HTTP Request error: 403 Client Error: Forbidden

Davide.

0 Karma

Damien_Dallimor
Ultra Champion

When you setup your REST input in Splunk Web , behind the scenes this data gets persisted to inputs.conf within your current app context.

This will help you find your stanza you created.

cd $SPLUNK_HOME/etc/apps

find . -name inputs.conf | xargs grep NAME_OF_YOUR_REST_STANZA

0 Karma

Damien_Dallimor
Ultra Champion

Can you please post what your REST Stanza you configured looks like (mask out any sensitive info).

This stanza gets persisted to inputs.conf ,so just search for it under SPLUNK_HOME/etc/apps

And also an example of your successful CURL command so I can correlate and look at what you may have setup wrong.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

The Trust Gap: Why a Data Foundation is Fundamental to an Agentic Enterprise

The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming ...

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...