Getting Data In

Injesting data through search api?

nitsrini
Loves-to-Learn

Is there any way we can inject data to one running Splunk enterprise(on premise) to another through search API? I can find the configured search APIs for Splunk (https://docs.splunk.com/Documentation/Splunk/8.1.2/RESTTUT/RESTsearches) , But searching for a way to inject data through these endpoints without using forwarder .Is this possible? 

0 Karma

somesoni2
Revered Legend

Could you provide more details on what type of data you're transferring from one Splunk instance to another and reason behind it?

0 Karma

nitsrini
Loves-to-Learn

 @somesoni2  since the documentation provided a way for getting log files data through REST , I was wondering is there  any REST API configuration available in Splunk enterprise for receiving the search data from another running instance of it.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

You could try the receivers/simple endpoint but I haven't used it myself so can't tell you whether it's a good idea. I mostly use HEC.

0 Karma
Get Updates on the Splunk Community!

Full-Stack Security in Financial Services: AppDynamics, Cisco Secure Application, and ...

Full-Stack Security in Financial Services: AppDynamics, Cisco Secure Application, and Splunk ES Protecting a ...

It's Customer Success Time at .conf25

Hello Splunkers,   Ready for .conf25? The customer success and experience team is and can’t wait to see you ...

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...