All Apps and Add-ons

Possible to ingest REST API JSON data with splunk initiating poll?

pir8radio
Path Finder

I want splunk to reach out to a few goofy devices on my network and grab JSON responses. Is this possible? can I get a few examples?

So to be clear i would like splunk to poll (reach out) say http://dummy.restapiexample.com/api/v1/employees every 10 seconds, this rest API with json response, and log this in an index so i can do my thing in splunk with the data. 🙂

0 Karma
1 Solution

wwhite12
Path Finder

The Splunk REST Modular Input app will give you the REST API option when you go to Settings >> Add Data >> Monitor like this, here you can set the interval, what response type, sourctype, etc. It will require an activation key from the developer, BaboonBones, not sure if that means $$$ or not
https://splunkbase.splunk.com/app/1546/#/overview
alt text

View solution in original post

0 Karma

wwhite12
Path Finder

The Splunk REST Modular Input app will give you the REST API option when you go to Settings >> Add Data >> Monitor like this, here you can set the interval, what response type, sourctype, etc. It will require an activation key from the developer, BaboonBones, not sure if that means $$$ or not
https://splunkbase.splunk.com/app/1546/#/overview
alt text

0 Karma

pir8radio
Path Finder

cool, i didnt know that plugin existed, ill see what it costs.. thx.

0 Karma

to4kawa
Ultra Champion

pir8radio
Path Finder

addon builder? Do you have some setup examples as to how i would make it work with the above REST API link?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Check the docs for AddOn builder - Addon Builder Docs @ Splunk

There are examples there how to create inputs, test the data pull, perform and normalize field extractions. All good stuff, and not too difficult to understand.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...