All Apps and Add-ons

Splunk Add-on Builder ::=> API requested data to KV Stores

kashz
Explorer

Using Add-on Builder:

Using Modular Input Python Code: I fetched the API data in JSON value, need to store in KV-Stores.

But the Add-on Builder Python Helper Functions (https://docs.splunk.com/Documentation/AddonBuilder/2.2.0/UserGuide/PythonHelperFunctions1) only specify write_to_index approach.
Is there an approach to store to KV-stores?

0 Karma
1 Solution

lakshman239
SplunkTrust
SplunkTrust
0 Karma

lakshman239
SplunkTrust
SplunkTrust
0 Karma

chli_splunk
Splunk Employee
Splunk Employee

You can use following functions to do this, although they are designed for checkpoint...

# save checkpoint
helper.save_check_point(key, state)
# delete checkpoint
helper.delete_check_point(key)
# get checkpoint
state = helper.get_check_point(key)
0 Karma

kashz
Explorer

It will not work as my JSON returned from the API is not just a single {key: value} which checkpoint accepts.
I have multi-key-valued JSON with nested key-value pairs.

0 Karma

chli_splunk
Splunk Employee
Splunk Employee

Can you give a name of your JSON as a key? You can also check the source codes of helper function, or REST API to operate Splunk KVStore.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...