All Apps and Add-ons

Possible to ingest REST API JSON data with splunk initiating poll?

pir8radio
Path Finder

I want splunk to reach out to a few goofy devices on my network and grab JSON responses. Is this possible? can I get a few examples?

So to be clear i would like splunk to poll (reach out) say http://dummy.restapiexample.com/api/v1/employees every 10 seconds, this rest API with json response, and log this in an index so i can do my thing in splunk with the data. 🙂

0 Karma
1 Solution

wwhite12
Path Finder

The Splunk REST Modular Input app will give you the REST API option when you go to Settings >> Add Data >> Monitor like this, here you can set the interval, what response type, sourctype, etc. It will require an activation key from the developer, BaboonBones, not sure if that means $$$ or not
https://splunkbase.splunk.com/app/1546/#/overview
alt text

View solution in original post

0 Karma

wwhite12
Path Finder

The Splunk REST Modular Input app will give you the REST API option when you go to Settings >> Add Data >> Monitor like this, here you can set the interval, what response type, sourctype, etc. It will require an activation key from the developer, BaboonBones, not sure if that means $$$ or not
https://splunkbase.splunk.com/app/1546/#/overview
alt text

0 Karma

pir8radio
Path Finder

cool, i didnt know that plugin existed, ill see what it costs.. thx.

0 Karma

to4kawa
Ultra Champion

pir8radio
Path Finder

addon builder? Do you have some setup examples as to how i would make it work with the above REST API link?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Check the docs for AddOn builder - Addon Builder Docs @ Splunk

There are examples there how to create inputs, test the data pull, perform and normalize field extractions. All good stuff, and not too difficult to understand.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...