All Apps and Add-ons

REST API Modular Input: Where do I need to make configuration changes to set up a new REST API call?

peetchow
Loves-to-Learn Lots

All,

I installed the REST API Modular Input add-on ( app 1546) and configured it to get twitter feeds from http discoveredintelligence . ca / stream-twitter-splunk-10-simple-steps .... sorry I do not have enough points to post links

It was working great with Splunk seeing the fields and stripping them out for the "Interesting Fields" section. We wanted to modify the REST API call and add some more tags to ingest into splunk. The instructions told us that the API Call configuration would be in etc/system/loca/inputs.conf and sure enough it was there. We edit the config and added a few more tags ... restarted Splunk and there the new tags where injested. We noticed that we were just getting tags and not actual tweets from specific users, so I figured we create a new API call for "follows" to ingest tweets on specific people we "follow".

Instead it was suggested to just copy the config in the inputs.conf and modify it. This was done and after restarting Splunk ... splunk stopped stripping out "interesting fields"

I figured doing the copy of the config messed it up, so I decided to clear out the twitter index and delete the REST API app and reinstall it and start fresh.

I did this, but every time I re-install the REST API add-on, twitter data just starts flowing back into the twitter index even before I can enter a new API call. I cleared the config from inputs.conf and deleted the REST API ... where else can there be configurations for the API call that is causing the API to call automatically upon re-installation with out setting up the new API Call ??

Any help would be great !

Thanks
Pete

0 Karma

Damien_Dallimor
Ultra Champion

Search for all "inputs.conf" files under SPLUNK_HOME/etc/apps , and in these files search for "rest".

0 Karma

peetchow
Loves-to-Learn Lots

I found it in /apps/launcher/local/inputs.conf !

So i can delete the rest stanzas in here and should be good to go with the re-install right?

to modify rest calls ... can i normally edit in the input.conf or is it best to just create new ones?

thanks!

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...