Splunk Dev

Monitoring App

jet
Explorer

I have a published app on SplunkBase which is designed to pull event data via API from an App which I publish to Splunk with. It's been working fine for several years.

A recent request from users is for more realtime data which would require me to pull data from API. It's not really suitable for logging and where I have done this before on an iPhone app, I held in ram as opposed to being "logged".

Ideally I would want to pull data once and for the response to be shared across multiple users as opposed to many users each individually polling data.

Is this something that is possible with a Splunk app? 

Labels (5)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The app can pull the data once (or periodically) and store it in a lookup.  Then it's available to users from the lookup.

---
If this reply helps you, Karma would be appreciated.

jet
Explorer

That helps! Upvote for you.

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...