Hello Team,
I have to collect and import data into Splunk, provided by a REST API.
How would it be possible to do?
Scenario:
As soon as I receive a notification that data is ready I need to execute the REST call to get the data.
Data is in json format and these data have to end up in Splunk.
Do I need to implement something custom, to save the response into a file for Splunk Fw to read?
or does Splunk offer something that works out of the box?
Thank you in advance,
chtamp
Hi @chtamp
You can try this modinput - REST API Modular Input | Splunkbase
Otherwise you have to write custom logic to get notified by App and initiate querying the REST API and ingest to Splunk via HEC token with acknowledgement mode enabled.
----------------------------------------
An upvote would be appreciated if it helps!