Splunk Cloud Platform

Is it possible to add Custom API for data input without interfering with existing official Qualys API?

vcanal
Explorer

Hello,

Sorry in advance if the question has already been asked, but I couldn't find anything.

I'm currently working with Qualys logs on Splunk. The Qualys API to pull data into Splunk is already configured, but there are several informations that the API does not retrieve, for example software installed on scanned computers.

So the question is, is it possible to add a custom API into Splunk without interfering with the existing official Qualys API ? And is there limitations for programming languages, or maybe it depends on the server on which my Splunk is running ?

Thank you in advance

Labels (1)
0 Karma
1 Solution

vcanal
Explorer

UPDATE :

Here some complementary information about my issue: the Qualys module I was trying to retrieve on my company's Splunk was Qualys Global AssetView (GAV), which data is not retrieved by the Qualys TA on Splunk. (Thank you anyway @richgalloway !)

So I ended up just creating a simple script to request information through the GAV API and added it as a scripted input on Splunk.

View solution in original post

vcanal
Explorer

UPDATE :

Here some complementary information about my issue: the Qualys module I was trying to retrieve on my company's Splunk was Qualys Global AssetView (GAV), which data is not retrieved by the Qualys TA on Splunk. (Thank you anyway @richgalloway !)

So I ended up just creating a simple script to request information through the GAV API and added it as a scripted input on Splunk.

richgalloway
SplunkTrust
SplunkTrust

It appears as though you are using "API" to mean "TA".  If so then, yes, you can create your own TA to retrieve the desired information.  Take care, however, to avoid using the same names as the Qualys TA or you risk unexpected behavior.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...