I have some data this is only retrievable via REST, and want to use it for a lookup. The data changes daily, so I need to run it at least once a day. Is there anyway to schedule a rest call to an external system and save it as a lookup?
Yes, you can use the REST modular input app:
Once you have data indexed into Splunk, you can run a scheduled search to export the data using the outputlookup command.
Your other option would be to write an external lookup that queries your REST API.
If your data only changes once a day, and you use the lookup frequently, a CSV lookup will probably be the better choice.
Try a custom search command that reads from the REST Endpoint and then you can pipe to outputlookup.
| myrestcommand | outputlookup myrestlookup
Here is a code example : https://github.com/splunk/splunk-demo-yelp-search-command
You can then schedule this by way of a scheduled search
I would expect you to support your own REST API modular input mentioned above 😉
Saving REST API output into an index will allow tracking of changes. And lookup export of recent data should work perfectly for the requested need!
Thanks for your very useful addon!