Kind of an off the wall question here. Does anyone know of an API or a way to query our Splunk support portal accounts to pull ticket information? Would love to be able to create a dashboard on-prem detailing open tickets, then if possible pull open/close timestamps and overlay that onto a visualization showing potential event drops during the time span of the case being open.
You can create one python script which will fire Splunk Portal and Fetch All the required information from Splunk Portal and Send it to Splunk Using HEC or on any port. And this script will run at some defined interval.