Getting Data In

Add multiple similar REST endpoints under 1 data input

cdtinsley1
Observer

I am trying use REST API modular input in order to get data in Splunk from a REST endpoint. Unfortunately to get all the data I need to add data from an ever increasing number for URL's. Let me try to explain better.

https://[URL for the API]/ is a top level for the API. This contains common data for across each collection of information I need from the API. 1 piece of information contained in here is ID, this can be appended to the URL to bring back detailed information on that 1 thing. I can successfully get into Splunk from this with a very simply configuration

https://[URL for the API]/[ID]  this is the detailed information about 1 record in the top level of the API. Currently there are thousands of these and it is growing. So far I cannot find a way to get this data into Splunk without setting up individual data inputs for each 1.

Is there a way to get data from every ID sub page into Splunk through setting variables or wildcards in the configuration of a REST API modular data input, or am I on the wrong path and I need to take a completely different route to solving this?

Labels (1)
Tags (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...

Keep the Learning Going with the New Best of .conf Hub

Hello Splunkers, With .conf26 getting closer, there’s already a lot of excitement building around this year’s ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...