Hi,
I am trying to get DATA into SPLUNK from my vcloud director environment.
I am using the REST API Modular Input app but I am always getting a HTTP Request error: 403 Client Error: Forbidden.
I am using basic authentication and with same details/credentials I am able to use curl or Mozilla RestClient to query vcloud director API succesful.
Has anyone had any experience in importing data from vcloud director into splunk using API?
Thanks,
Davide.
Here you are:
[root@r2-prdcldnfs apps]# find . -name inputs.conf | xargs grep vcloud_rest
./launcher/local/inputs.conf:[rest://vcloud_rest]
[root@r2-prdcldnfs apps]# cat ./launcher/local/inputs.conf
[rest://vcloud_rest]
auth_password = Password
auth_type = basic
auth_user = sale1@Sales-LAB
endpoint = https://10.0.0.21/api/query
http_header_propertys = Accept=application/*+xml,version=1.5
http_method = GET
index_error_response_codes = 0
response_type = xml
streaming_request = 0
url_args = type=task,format=records
[root@r2-prdcldnfs apps]#
In /opt/splunk/var/log/splunk/splunkd.log I always get
10-28-2014 09:41:53.214 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/rest_ta/bin/rest.py" HTTP Request error: 403 Client Error: Forbidden
Davide.
When you setup your REST input in Splunk Web , behind the scenes this data gets persisted to inputs.conf within your current app context.
This will help you find your stanza you created.
cd $SPLUNK_HOME/etc/apps
find . -name inputs.conf | xargs grep NAME_OF_YOUR_REST_STANZA
Can you please post what your REST Stanza you configured looks like (mask out any sensitive info).
This stanza gets persisted to inputs.conf ,so just search for it under SPLUNK_HOME/etc/apps
And also an example of your successful CURL command so I can correlate and look at what you may have setup wrong.