Knowledge Management

How can I populate a host tag from an external source?

jedatt01
Builder

I have a list of hosts that are assigned to a tag so the user doesn't have to input the list of hosts manually in search. These hosts are changed occasionally and I have an external system that manages those changes. Is there any way to pull the host changes from the external system (which has an api) and dynamically populate my tags instead of manually changing them.

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You can edit tags through Splunk's REST API: http://docs.splunk.com/Documentation/Splunk/latest/RESTREF/RESTknowledge#search.2Ftags

If you need Splunk to be the active "pulling" part, you could build a scripted or modular input that runs on a schedule, queries your external source, makes REST calls accordingly (and logs to Splunk, obviously).

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...