All Apps and Add-ons

Possible to ingest REST API JSON data with splunk initiating poll?

pir8radio
Path Finder

I want splunk to reach out to a few goofy devices on my network and grab JSON responses. Is this possible? can I get a few examples?

So to be clear i would like splunk to poll (reach out) say http://dummy.restapiexample.com/api/v1/employees every 10 seconds, this rest API with json response, and log this in an index so i can do my thing in splunk with the data. 🙂

0 Karma
1 Solution

wwhite12
Path Finder

The Splunk REST Modular Input app will give you the REST API option when you go to Settings >> Add Data >> Monitor like this, here you can set the interval, what response type, sourctype, etc. It will require an activation key from the developer, BaboonBones, not sure if that means $$$ or not
https://splunkbase.splunk.com/app/1546/#/overview
alt text

View solution in original post

0 Karma

wwhite12
Path Finder

The Splunk REST Modular Input app will give you the REST API option when you go to Settings >> Add Data >> Monitor like this, here you can set the interval, what response type, sourctype, etc. It will require an activation key from the developer, BaboonBones, not sure if that means $$$ or not
https://splunkbase.splunk.com/app/1546/#/overview
alt text

0 Karma

pir8radio
Path Finder

cool, i didnt know that plugin existed, ill see what it costs.. thx.

0 Karma

to4kawa
Ultra Champion

pir8radio
Path Finder

addon builder? Do you have some setup examples as to how i would make it work with the above REST API link?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Check the docs for AddOn builder - Addon Builder Docs @ Splunk

There are examples there how to create inputs, test the data pull, perform and normalize field extractions. All good stuff, and not too difficult to understand.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...