All Apps and Add-ons

Splunk Add-on Builder ::=> API requested data to KV Stores

kashz
Explorer

Using Add-on Builder:

Using Modular Input Python Code: I fetched the API data in JSON value, need to store in KV-Stores.

But the Add-on Builder Python Helper Functions (https://docs.splunk.com/Documentation/AddonBuilder/2.2.0/UserGuide/PythonHelperFunctions1) only specify write_to_index approach.
Is there an approach to store to KV-stores?

0 Karma
1 Solution

lakshman239
SplunkTrust
SplunkTrust
0 Karma

lakshman239
SplunkTrust
SplunkTrust
0 Karma

chli_splunk
Splunk Employee
Splunk Employee

You can use following functions to do this, although they are designed for checkpoint...

# save checkpoint
helper.save_check_point(key, state)
# delete checkpoint
helper.delete_check_point(key)
# get checkpoint
state = helper.get_check_point(key)
0 Karma

kashz
Explorer

It will not work as my JSON returned from the API is not just a single {key: value} which checkpoint accepts.
I have multi-key-valued JSON with nested key-value pairs.

0 Karma

chli_splunk
Splunk Employee
Splunk Employee

Can you give a name of your JSON as a key? You can also check the source codes of helper function, or REST API to operate Splunk KVStore.

0 Karma
Get Updates on the Splunk Community!

Platform Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestIntroducing Splunk Edge Processor, simplified data ...

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...