Splunk Dev

Can my Splunk app listen for all incoming log events?

nohyei6v
Explorer

I am new to Splunk but would like to make a plugin for others to use: it should read all incoming events and scan them for certain contents. As an example (this is not my use case), imagine the app would look for IP addresses being logged. It would then use any IP addresses it finds, check them for a certain property (e.g. reachability), and create new log entries if relevant.

The part I can't find in the documentation (or ducking/googling) is how to listen for events. Using the Add-on Builder I got to the point where my Python code gets called every X seconds, but there does not seem to be a way to register a callback for log entries. Is this possible?

One workaround I can think of is using the "every X seconds" callback (collect_events(helper, ew)) to perform a search in Splunk for events that occurred between now and X seconds ago (or perhaps search any events with a higher ID than the highest resulting ID of the previous search), but it seems rather inefficient. Would this be the way to implement this?

Labels (2)
0 Karma
1 Solution

starcher
SplunkTrust
SplunkTrust

That is not how splunk addons work. You don't listen to incoming events. The search over indexed data would be the correct method.

View solution in original post

starcher
SplunkTrust
SplunkTrust

That is not how splunk addons work. You don't listen to incoming events. The search over indexed data would be the correct method.

nohyei6v
Explorer

Thanks for the response! Odd that Splunk doesn't implement something so basic as running the data through some custom code for additional functionality, I expected that to be core to many add-ons.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Using the Splunk Threat Research Team’s Latest Security Content

REGISTER HERE Tech Talk | Security Edition Did you know the Splunk Threat Research Team regularly releases ...

SplunkTrust | 2024 SplunkTrust Application Period is Open!

It's that time again, folks! That's right, the application/nomination period for the 2024 SplunkTrust is ...