Getting Data In

Injesting data through search api?

nitsrini
Loves-to-Learn

Is there any way we can inject data to one running Splunk enterprise(on premise) to another through search API? I can find the configured search APIs for Splunk (https://docs.splunk.com/Documentation/Splunk/8.1.2/RESTTUT/RESTsearches) , But searching for a way to inject data through these endpoints without using forwarder .Is this possible? 

0 Karma

somesoni2
Revered Legend

Could you provide more details on what type of data you're transferring from one Splunk instance to another and reason behind it?

0 Karma

nitsrini
Loves-to-Learn

 @somesoni2  since the documentation provided a way for getting log files data through REST , I was wondering is there  any REST API configuration available in Splunk enterprise for receiving the search data from another running instance of it.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

You could try the receivers/simple endpoint but I haven't used it myself so can't tell you whether it's a good idea. I mostly use HEC.

0 Karma
Get Updates on the Splunk Community!

Operationalizing TDIR: Building a More Resilient, Scalable SOC

Optimizing SOC workflows with a unified, risk-based approach to Threat Detection, Investigation, and Response ...

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...

Raise Your Skills at the .conf25 Builder Bar: Your Splunk Developer Destination

Calling all Splunk developers, custom SPL builders, dashboarders, and Splunkbase app creators – the Builder ...