Is it possible to load a CSV file to Splunk only by using a REST API search?
I have Splunk installed on another machine and I need to have the ability to load data to the Splunk, let's say from any place all over the world.
Please advise how this REST API should look like if this possible.
Do I need to perform some additional changes in configuration?
Personally I think streaming the data using either a Universal Fowarder or a remote TCP input is a better idea. If your data is not suitable for streaming (ie it is not time series data) consider using a lookup or KV store instead of indexing the data (or use a database)
You could use a shellscript to step through the CSV and send line as individual events. For example (where foo bar and baz are your column headers) the following script will send an event for each line in your csv