Getting Data In

How to automatically call REST API on specific event field?

Autom8teMe
Observer

I have an external API subscription that I want to call when a specific field in my Splunk event is present (e.g. City_Name). The REST API call would query the external API for <City_Name> and add the returned data (in JSON format) into Splunk to enrich the event.

I've seen something similar with using "lookup" but looking for a tutorial on how to build this so that when the event field is present, the external API can be called to download the additional enrichment data.

Suggestions / tutorials on how I might go about implementing this in Splunk?

Thanks.

Labels (2)
Tags (3)
0 Karma
Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Enhance Security Operations with Automated Threat Analysis in the Splunk EcosystemAre you leveraging ...

Splunk Developers: Go Beyond the Dashboard with These .Conf25 Sessions

  Whether you’re building custom apps, diving into SPL2, or integrating AI and machine learning into your ...

Index This | How do you write 23 only using the number 2?

July 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...