Splunk Enterprise

Getting data in Splunk through REST API in case of two step connection

AKG1_old1
Builder

Hello,I am trying to connect App to get data in Splunk using REST API. The issue is that REST API request need to be implemented in 2 steps.

Send POST request to get the token (valid for 24 hrs)

Send GET request to fetch the results using token from first request.

I am able to implement two separate requests. But looking to automate this process. My idea is to write a script which will periodically copy the token values to input configuration file.

FYI:I have used Rest API Modular input app for these request.

Problems: Splunk Server is on windows. Using Rest API Modular Input App, It sending token results directly to Splunk server not sure how to get that on windows machine. If its linux I would have write a bash script which use curl to fetch token value and paste it to input configuration. Not sure how to perform this on windows.

Thanks

Labels (1)
Tags (2)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...