Hi all,
I am trying to configure a REST API (OAuth) into a Splunk cloud trial environment. I'm running into issues and not seeing a clear way to pull this data in. I've tried using the HTTP event collector with no luck.
I want to consume and search on the events that are pulled. Could this be a limitation on my cloud trial? Anything I'm missing?
I did find an app called "REST API Modular Input" that seems to work with splunk enterprise, but not splunk cloud. is there a free equivalent on splunk cloud splunkbase?
Thanks,
Michelle
General guidance has been to run inputs on an on-prem heavy forwarder (HF) that forwards the data it collects to Splunk Cloud. That changes with the Victoria experience, but is limited by apps that are approved for Cloud. Unapproved apps have to be run on an HF.