Getting Data In

Send data from Splunk

tonyArad
Engager

Is it possible to use Splunk as a data storage server and build an application that will send the data contained by Splunk by REST API to another server?

Tags (1)
0 Karma
1 Solution

amit_saxena
Communicator

Hi,

While REST API and SDK allows you to integrate Splunk with third party applications, you can also use custom scripts etc for the same if the third party application has a provision for the same.

You can use alerts feature in Splunk to call custom third party scripts / command line binary etc to pass on the search data from Splunk to third party application.

Let me know if you have any queries on this.

Regards,
Amit Saxena

View solution in original post

0 Karma

amit_saxena
Communicator

Hi,

While REST API and SDK allows you to integrate Splunk with third party applications, you can also use custom scripts etc for the same if the third party application has a provision for the same.

You can use alerts feature in Splunk to call custom third party scripts / command line binary etc to pass on the search data from Splunk to third party application.

Let me know if you have any queries on this.

Regards,
Amit Saxena

0 Karma

amit_saxena
Communicator

Hi Tony,

You can use any programming language of your choice ( which has capability to work with REST API calls ) and then use the REST API depending upon your requirement. For details on REST API, you can refer the Splunk REST API documentation at http://docs.splunk.com/Documentation/Splunk/latest/RESTAPI/RESTcontents .

Note : As "davecroto" has mentioned in later post, you can also use Splunk SDK available in few languages which acts like a wrapper over REST API to do the tasks thus simplifying the overall tasks.

Let me know if you have more queries on this.

Regards,
Amit Saxena

0 Karma

tonyArad
Engager

Hi Amit,
Thank you for your answer.
Can you please elaborate on the script/command needed in order to send out data? how do I configure it?
Thanks again!
Tony

0 Karma

davecroto
Splunk Employee
Splunk Employee

Yes, Integrate with third-party tools and or portals using the SDK language of your choice.

http://dev.splunk.com/view/splunk-sdk/SP-CAAADP7

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...