Dashboards & Visualizations

Trigger a SOAP request after field check

DotTest37
Path Finder

I have a request for something rather complex.

I have a Web App behind a BigIP load balancer, I set the BigIP to send me the whole transaction to splunk as it happens.
Im extracting already the fiels,, and I need the following:
- As soon as one XML response comes back with certain combination of the two fields, I need to trigger a SOAP request, get the answer and display on splunk again.

Can Splunk trigger a SOAP request based on a condition of values received as input?

Tags (2)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

If you simply mean that you want to look up a value from an external system when viewing results, then you might be looking for a scripted lookup.

If you mean for some program to be triggered when Splunk sees some matching condition based on indexed data, then you probably need a real-time alert, triggering a program you can provide to run the request.

It's not clear what you mean, because you mention "as soon as a response" comes back, implying this is something that should happen when data is indexed, but you also mention "displaying" it in Splunk, implying that this only happens when there is a user interacting and searching data.

0 Karma

DotTest37
Path Finder

(Obviusly, the Balancer will send the whole request and answer from that transaction back to Splunk since it is sending everything anyways,, so I dont think I need to do anything else on splunk,, other than take the phone number (when the Flag is false) and add it as parameter on the new SOAP request)
Im looking for where to start 🙂
Thanks!!

0 Karma

DotTest37
Path Finder

Let me see if I explain better:
-I have an F5 load Balancer, the web app behind takes parameters on a SOAP requests (username, password, etc, and a phone number),, then it responds with an XML stream, with some values, and also a TRUE/FALSE flag. All those requests are sent via syslog to my Splunk.
I need to make Splunk, to generate another SOAP request to the Web Application , everytime the answer contains the flag FALSE (using that phone number as parameter for the request).

guarisma
Contributor

Did you find a solution?
I'm about to start something similar by creating my own alert_ app

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...