Knowledge Management

How can I populate a host tag from an external source?

jedatt01
Builder

I have a list of hosts that are assigned to a tag so the user doesn't have to input the list of hosts manually in search. These hosts are changed occasionally and I have an external system that manages those changes. Is there any way to pull the host changes from the external system (which has an api) and dynamically populate my tags instead of manually changing them.

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You can edit tags through Splunk's REST API: http://docs.splunk.com/Documentation/Splunk/latest/RESTREF/RESTknowledge#search.2Ftags

If you need Splunk to be the active "pulling" part, you could build a scripted or modular input that runs on a schedule, queries your external source, makes REST calls accordingly (and logs to Splunk, obviously).

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...