Getting Data In

Is there a way for Splunk to Call Third Party REST APIs Dynamically?

premrajvs
Explorer

Requirement : Call REST APIs and ingest the data into Splunk to specified indexes

As of now, we are using Splunk Add on Builder Application to create apps for REST API calls and importing the data into Splunk.

Limitation with this approach : We are not able to call an API dynamically  or on ad-hoc basis only when needed. Team wants to have an UI to call the REST APIs dynamically and show this data into a dashboard.

Is there any way in Splunk to provide this capability ?

Labels (1)
0 Karma
1 Solution

premrajvs
Explorer

I think there is no app available to call APIs on adhoc basis. So, I am building my own custom app.

View solution in original post

bowesmana
SplunkTrust
SplunkTrust

Yes, you can use curl as part of SPL with this app

https://splunkbase.splunk.com/app/4146

 

0 Karma

premrajvs
Explorer

I think there is no app available to call APIs on adhoc basis. So, I am building my own custom app.

richgalloway
SplunkTrust
SplunkTrust

Have you looked at the REST API Modular Input app (https://splunkbase.splunk.com/app/1546)?  It's not truly ad-hoc, but is more so than building code with AoB.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...