Splunk Cloud Platform

Is it possible to add Custom API for data input without interfering with existing official Qualys API?

vcanal
Explorer

Hello,

Sorry in advance if the question has already been asked, but I couldn't find anything.

I'm currently working with Qualys logs on Splunk. The Qualys API to pull data into Splunk is already configured, but there are several informations that the API does not retrieve, for example software installed on scanned computers.

So the question is, is it possible to add a custom API into Splunk without interfering with the existing official Qualys API ? And is there limitations for programming languages, or maybe it depends on the server on which my Splunk is running ?

Thank you in advance

Labels (1)
0 Karma
1 Solution

vcanal
Explorer

UPDATE :

Here some complementary information about my issue: the Qualys module I was trying to retrieve on my company's Splunk was Qualys Global AssetView (GAV), which data is not retrieved by the Qualys TA on Splunk. (Thank you anyway @richgalloway !)

So I ended up just creating a simple script to request information through the GAV API and added it as a scripted input on Splunk.

View solution in original post

vcanal
Explorer

UPDATE :

Here some complementary information about my issue: the Qualys module I was trying to retrieve on my company's Splunk was Qualys Global AssetView (GAV), which data is not retrieved by the Qualys TA on Splunk. (Thank you anyway @richgalloway !)

So I ended up just creating a simple script to request information through the GAV API and added it as a scripted input on Splunk.

richgalloway
SplunkTrust
SplunkTrust

It appears as though you are using "API" to mean "TA".  If so then, yes, you can create your own TA to retrieve the desired information.  Take care, however, to avoid using the same names as the Qualys TA or you risk unexpected behavior.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...