Getting Data In

RSS Feeds or Email notification as Data Inputs

kkumarm
New Member

Hi,

I would like to know if there is any way in which rss feeds or email notification from remote systems can be taken as data inputs in splunk ( am using a nms tool which has rss feeds and email notification)

Regards,

Mahesh

Tags (1)
0 Karma

amit_saxena
Communicator

Hi,

RSS can be read like a regular XML so you can use any language that has the capability of reading and extracting data from XML apart from fetching any web page.

Regards,
Amit Saxena

0 Karma

dwaddle
SplunkTrust
SplunkTrust

Yes you can.

For RSS, @ndoshi has already made an add-on app for reading RSS feeds and indexing them, see http://splunk-base.splunk.com/apps/22395/rss-scripted-input

For email, there are several ways of dealing with it. One is an app by Erik Swan, http://splunk-base.splunk.com/apps/22390/splunk-for-imap. Approaches using unix maildir or procmail is documented at http://splunk-base.splunk.com/answers/61093/how-can-i-convert-mailbox-or-maildir-to-splunk?page=1&fo...

Either way, the answer is yes you can do this, provided you are willing to do a little integration work yourself. Splunk does not provide this functionality "out of the box", but gives you the tools to do this for yourself in the form of scripted inputs and (new in 5.0) modular inputs.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...