Splunk Cloud Platform

Is it possible to add Custom API for data input without interfering with existing official Qualys API?

vcanal
Explorer

Hello,

Sorry in advance if the question has already been asked, but I couldn't find anything.

I'm currently working with Qualys logs on Splunk. The Qualys API to pull data into Splunk is already configured, but there are several informations that the API does not retrieve, for example software installed on scanned computers.

So the question is, is it possible to add a custom API into Splunk without interfering with the existing official Qualys API ? And is there limitations for programming languages, or maybe it depends on the server on which my Splunk is running ?

Thank you in advance

Labels (1)
0 Karma
1 Solution

vcanal
Explorer

UPDATE :

Here some complementary information about my issue: the Qualys module I was trying to retrieve on my company's Splunk was Qualys Global AssetView (GAV), which data is not retrieved by the Qualys TA on Splunk. (Thank you anyway @richgalloway !)

So I ended up just creating a simple script to request information through the GAV API and added it as a scripted input on Splunk.

View solution in original post

vcanal
Explorer

UPDATE :

Here some complementary information about my issue: the Qualys module I was trying to retrieve on my company's Splunk was Qualys Global AssetView (GAV), which data is not retrieved by the Qualys TA on Splunk. (Thank you anyway @richgalloway !)

So I ended up just creating a simple script to request information through the GAV API and added it as a scripted input on Splunk.

richgalloway
SplunkTrust
SplunkTrust

It appears as though you are using "API" to mean "TA".  If so then, yes, you can create your own TA to retrieve the desired information.  Take care, however, to avoid using the same names as the Qualys TA or you risk unexpected behavior.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...