All Apps and Add-ons

What's the use of Gitlab add-on?

ww9rivers
Contributor

Specifically, this statement prompted my question: "If you do not specify a specific project ID, you will only get event data associated with the account the token is associated with."

So does the add-on only gets event data either associated with one account, or one project?

jstrille
Engager

Hello,
From what I understand of my usage of it: it gets all events across all projects that you have the right to view with the specified token.
If you specify a project it will only get events you have the right to view on the specified project.

0 Karma

ww9rivers
Contributor

Thank you. I manage Splunk but am only a client side gitlab user, so please bear with me asking more questions.

So from Splunk's perspective, say I would like to collect all events for all projects on a gitlab server, I would need to set up a "super user" in the gitlab installation, which would automatically have rights to access all existing and to-be-created projects?

Regards.

0 Karma

jstrille
Engager

Exactly or an admin account on which you create a token with the API scope.
However this TA doesn't work as well as expected from my testings: there is no pagination handling which is fine for retrieving current /events but you won't be importing all the history of the different sourcetypes provided by the TA.

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...