All Apps and Add-ons

indexing data with importutil

toumii
Engager

Hi everyone,

I am trying to index using http. I used importutil. But I think i'm misusing it, since I can't figure how to index data shown by the command (importutil). Here's what I did:

|importutil http (url)

Tha data is shown but not indexed.

Thank you very much for helping

Tags (3)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

According to the documentation at https://splunkbase.splunk.com/app/1311/#/documentation importutil doesn't index anything, it provides input to build lookup files.

Consider using the REST modular input: https://splunkbase.splunk.com/app/1546/

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

According to the documentation at https://splunkbase.splunk.com/app/1311/#/documentation importutil doesn't index anything, it provides input to build lookup files.

Consider using the REST modular input: https://splunkbase.splunk.com/app/1546/

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...