Splunk Cloud Platform

Is it possible to add Custom API for data input without interfering with existing official Qualys API?

vcanal
Explorer

Hello,

Sorry in advance if the question has already been asked, but I couldn't find anything.

I'm currently working with Qualys logs on Splunk. The Qualys API to pull data into Splunk is already configured, but there are several informations that the API does not retrieve, for example software installed on scanned computers.

So the question is, is it possible to add a custom API into Splunk without interfering with the existing official Qualys API ? And is there limitations for programming languages, or maybe it depends on the server on which my Splunk is running ?

Thank you in advance

Labels (1)
0 Karma
1 Solution

vcanal
Explorer

UPDATE :

Here some complementary information about my issue: the Qualys module I was trying to retrieve on my company's Splunk was Qualys Global AssetView (GAV), which data is not retrieved by the Qualys TA on Splunk. (Thank you anyway @richgalloway !)

So I ended up just creating a simple script to request information through the GAV API and added it as a scripted input on Splunk.

View solution in original post

vcanal
Explorer

UPDATE :

Here some complementary information about my issue: the Qualys module I was trying to retrieve on my company's Splunk was Qualys Global AssetView (GAV), which data is not retrieved by the Qualys TA on Splunk. (Thank you anyway @richgalloway !)

So I ended up just creating a simple script to request information through the GAV API and added it as a scripted input on Splunk.

richgalloway
SplunkTrust
SplunkTrust

It appears as though you are using "API" to mean "TA".  If so then, yes, you can create your own TA to retrieve the desired information.  Take care, however, to avoid using the same names as the Qualys TA or you risk unexpected behavior.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...