All Apps and Add-ons

Possible to ingest REST API JSON data with splunk initiating poll?

pir8radio
Path Finder

I want splunk to reach out to a few goofy devices on my network and grab JSON responses. Is this possible? can I get a few examples?

So to be clear i would like splunk to poll (reach out) say http://dummy.restapiexample.com/api/v1/employees every 10 seconds, this rest API with json response, and log this in an index so i can do my thing in splunk with the data. 🙂

0 Karma
1 Solution

wwhite12
Path Finder

The Splunk REST Modular Input app will give you the REST API option when you go to Settings >> Add Data >> Monitor like this, here you can set the interval, what response type, sourctype, etc. It will require an activation key from the developer, BaboonBones, not sure if that means $$$ or not
https://splunkbase.splunk.com/app/1546/#/overview
alt text

View solution in original post

0 Karma

wwhite12
Path Finder

The Splunk REST Modular Input app will give you the REST API option when you go to Settings >> Add Data >> Monitor like this, here you can set the interval, what response type, sourctype, etc. It will require an activation key from the developer, BaboonBones, not sure if that means $$$ or not
https://splunkbase.splunk.com/app/1546/#/overview
alt text

0 Karma

pir8radio
Path Finder

cool, i didnt know that plugin existed, ill see what it costs.. thx.

0 Karma

to4kawa
Ultra Champion

pir8radio
Path Finder

addon builder? Do you have some setup examples as to how i would make it work with the above REST API link?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Check the docs for AddOn builder - Addon Builder Docs @ Splunk

There are examples there how to create inputs, test the data pull, perform and normalize field extractions. All good stuff, and not too difficult to understand.

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...