All Apps and Add-ons

Indexing results from JKats Toolkit cURL

mrgibbon
Contributor

Hi All, Im just about to get cracking on a new project and want to know something before I start.
I'll be taking a look at the curl command in JKats Toolkit to retrieve data from an external system.
BUT, I don't want to view the data on a dashboard, I'd like to have it indexed instead.
Is it possible? If it is, how?

Thanks in advance!

0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

Yes that's exactly how I would do it. Collect, sistats, etc.

The premise of the command is to get the data into the search pipeline so that you can use Rex and other commands to manipulate it as you wish. There are updates coming and your input is welcomed and appreciated.

View solution in original post

jkat54
SplunkTrust
SplunkTrust

Yes that's exactly how I would do it. Collect, sistats, etc.

The premise of the command is to get the data into the search pipeline so that you can use Rex and other commands to manipulate it as you wish. There are updates coming and your input is welcomed and appreciated.

mrgibbon
Contributor

Thanks for the confirmation, I'd be eager to see any future updates!

0 Karma

jkat54
SplunkTrust
SplunkTrust

Next version should only use options instead of the current mix of keywords and options. So it will look like this

| curl uri=... method=... user=... pass=... data=...

after that the next goal is to encrypt the authentication settings in a conf file and give the option of connection_name=... Maybe include the uri in the conf file too (optionally).

0 Karma

jkat54
SplunkTrust
SplunkTrust

Thanks for your interest!

0 Karma

mrgibbon
Contributor

Could I use the collect command for instance? Or is there a better way? I dont want to use a summary index unless I really need to.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...