Splunk Enterprise

Getting data in Splunk through REST API in case of two step connection

AKG1_old1
Builder

Hello,I am trying to connect App to get data in Splunk using REST API. The issue is that REST API request need to be implemented in 2 steps.

Send POST request to get the token (valid for 24 hrs)

Send GET request to fetch the results using token from first request.

I am able to implement two separate requests. But looking to automate this process. My idea is to write a script which will periodically copy the token values to input configuration file.

FYI:I have used Rest API Modular input app for these request.

Problems: Splunk Server is on windows. Using Rest API Modular Input App, It sending token results directly to Splunk server not sure how to get that on windows machine. If its linux I would have write a bash script which use curl to fetch token value and paste it to input configuration. Not sure how to perform this on windows.

Thanks

Labels (1)
Tags (2)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...