All Apps and Add-ons

REST API Modular Input

ronak
Path Finder

Hi - I've downloaded the application that Damien Dallimore has created ...I'm assuming that this application will allow me to access external data source(s) using RST calls, get the data and index into my splunk instance.

Is my assumption correct?

Also, how do I configure this application to specify what to extract and from where....

When I open the application , it gives me a standard search bar, menu options like normal application. Any pointers would be great.

Thanks, ronak

0 Karma

Damien_Dallimor
Ultra Champion

It is not an App. It is a Modular Input Add-on.

Navigate to Data Inputs -> Rest - > New

The setup UI for a new REST input should be straightforward for most uses cases.

More advanced options are available for more complex uses cases. But start with the simple setup first and see how you go.

0 Karma

ronak
Path Finder

Thanks Damien ...highly appreciated. I'm still newbie to Splunk..

One more question in this regard if I may (I also have posted question on "Answers" ) - can REST API be used for executing search queries on user data, query summary models etc..Could not find any good reference. All the documentation of REST API pointed to accessing splunk configurations , updates etc...

0 Karma

Damien_Dallimor
Ultra Champion

This is not related to the REST API Modular Input.

But to answer your question , you can execute Splunk searches via Splunk's REST API : http://docs.splunk.com/Documentation/Splunk/6.2.1/RESTREF/RESTsearch

Further more , we have SDK's in various languages to make it easier to use the Splunk REST API to execute searches : http://dev.splunk.com/view/sdks/SP-CAAADP7

You'll find loads of examples under those links I posted.

0 Karma

ronak
Path Finder

Martin

Would you kindly share the steps meaning which directories and files I need to touch /modify, where to add these changes into configuration etc

Thanks, Ronak

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You assume correctly.

I know of two ways to influence what gets indexed - first, you can specify a regular expression that filters responses and only matches are indexed. Second, you can write a Python response handler that does whatever with the data returned by the REST endpoint before indexing.

0 Karma

ronak
Path Finder

Martin

Would you kindly share the steps meaning which directories and files I need to touch /modify, where to add these changes into configuration etc

Thanks, Ronak

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...