Getting Data In

Splunk Cloud Trial only shows 'HTTP Event Collector' as Data Input option

bluperfsplunkpo
Explorer

I am trying to test Scripted Input according to steps mentioned here -
docs splunk com /Documentation/SplunkCloud/8.0.2004/Data/Getdatafromscriptedinputs

The problem is that trial instance only shows HTTP Event Collector
alt text

What am I doing wrong? Or am I expecting something that Trial instance doesn't provide?

Thanks in advance!

Labels (1)
Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Splunk Cloud does not support scripted inputs. To use scripted inputs, you must define them in an on-prem heavy forwarder.
There's an exception for inputs from cloud-based sources, but I'm not sure the trial version supports IDM (Inputs Data Manager).

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Splunk Cloud does not support scripted inputs. To use scripted inputs, you must define them in an on-prem heavy forwarder.
There's an exception for inputs from cloud-based sources, but I'm not sure the trial version supports IDM (Inputs Data Manager).

---
If this reply helps you, Karma would be appreciated.

bluperfsplunkpo
Explorer

Thanks @richgalloway for the quick response! Just one follow-up question -

Is there any alternate way to index response from REST API?

One approach I see is with Splunk Enterprise + REST API Modular Input kind of solution
https://splunkbase.splunk.com/app/1546/#/overview

I am reasonably new to Splunk so if my question is not well-formed apologies in advance.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Modular inputs and scripted inputs are fraternal twins. Both require heavy forwarders to work with Splunk Cloud.

---
If this reply helps you, Karma would be appreciated.

bluperfsplunkpo
Explorer

Thanks again. This helped a lot!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...