All Apps and Add-ons

indexing data with importutil

toumii
Engager

Hi everyone,

I am trying to index using http. I used importutil. But I think i'm misusing it, since I can't figure how to index data shown by the command (importutil). Here's what I did:

|importutil http (url)

Tha data is shown but not indexed.

Thank you very much for helping

Tags (3)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

According to the documentation at https://splunkbase.splunk.com/app/1311/#/documentation importutil doesn't index anything, it provides input to build lookup files.

Consider using the REST modular input: https://splunkbase.splunk.com/app/1546/

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

According to the documentation at https://splunkbase.splunk.com/app/1311/#/documentation importutil doesn't index anything, it provides input to build lookup files.

Consider using the REST modular input: https://splunkbase.splunk.com/app/1546/

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...