All Apps and Add-ons

REST API option for compressed file? Can I index a zip file?

tamduong16
Contributor

I want to set up a REST API call to https get request but this site will return a zip file instead of xml, jason , or text. Is there a way I could set it to index the zip file? If not, is there any workaround? This is the description from the site:

alt text

0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

You can try using a custom response handler that will unzip the file for you.

  • Create a custom handler in $SPLUNK_HOME/etc/apps/rest_ta/bin/responsehandlers.py
  • Declare the handler in your configuration

Psuedo code examples :

alt text

alt text

View solution in original post

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @tamduong16, if @damien solved your problem, please close the question and award karma points by accepting the answer. 🙂 Happy Splunking!

0 Karma

Damien_Dallimor
Ultra Champion

You can try using a custom response handler that will unzip the file for you.

  • Create a custom handler in $SPLUNK_HOME/etc/apps/rest_ta/bin/responsehandlers.py
  • Declare the handler in your configuration

Psuedo code examples :

alt text

alt text

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...