All Apps and Add-ons

Rest URL startTime using checkpoint

BP9906
Builder

How do I get the Splunk AoB to use the checkpoint timestamp in the future URI requests?

I'm trying to have a default start time and then have it incremented based on what it saw last.

I end up with a inputs.conf.spec error when I attempt to use startTime in both REST URL parameters and in the checkpoint parameter name. Splunk complains about the checkpoint parameter name not being defined in inputs.conf.spec.

Unable to initialize modular input "test_audit_log" defined inside the app "TA-test-audit-collector": Endpoint argument "audit_time_checkpoint" has not been defined in the inputs.conf.spec file. All args defined via introspection must also be defined in the spec file.

0 Karma
1 Solution

BP9906
Builder

I found that I need to keep the checkpoint variable in all lowercase letters. Doing that resolved the error.

View solution in original post

0 Karma

Jasdeep
Explorer

issue resolved when I used checkpoint parameter name in lowercase.

0 Karma

BP9906
Builder

I found that I need to keep the checkpoint variable in all lowercase letters. Doing that resolved the error.

0 Karma

sirpatrick
Explorer

BP9906,

I have I think the same task at hand where my API has a start and end date option. I'd like to leverage the checkpoint to increment the start date in the next API call. My problem is that each JSON reply returns multiple records and the checkpointed field (created date/time) is in each but not necessarily in any order.  As such, I never know which is the latest date/time stamp.

Is there a way to find the highest value checkpoint and add 1 second to it for the next API start? How did you handle the increment?

0 Karma

ansif
Motivator

If you have used any checkpoint variable,just rename to something else and try.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...