Splunk Enterprise

How to make a custom REST endpoint in Splunk?

LukeMurphey
Champion

How do I make a custom REST endpoint in Splunk?
I am struggling to find documentation that explains how to make one.

1 Solution

LukeMurphey
Champion

See https://github.com/jrervin/splunk-rest-examples for examples of how to make a REST endpoint in Splunk.

There are also some helper libraries that you can use.

Here is a library for helping to create a REST handler for providing access to a custom .conf file: https://github.com/LukeMurphey/splunk-network-tools/blob/master/src/bin/network_tools_app/simple_res...

Here is a helper library for a generic REST endpoint: https://gist.github.com/LukeMurphey/238004c8976804a8e79570d22721fd99

View solution in original post

datphamtat
Explorer

But don't have an example for the POST endpoint. Overall, I think the document in Splunk is not good, not enough for a newbie. IBM QRadar and ELK have good document to development

0 Karma

thellmann
Splunk Employee
Splunk Employee

We've just released updated documentation on custom REST endpoints: https://dev.splunk.com/enterprise/docs/developapps/customrestendpoints/

Please let us know if this helps answer your question. We'd also love to hear about feedback or suggestions for improvement.

0 Karma

LukeMurphey
Champion

See https://github.com/jrervin/splunk-rest-examples for examples of how to make a REST endpoint in Splunk.

There are also some helper libraries that you can use.

Here is a library for helping to create a REST handler for providing access to a custom .conf file: https://github.com/LukeMurphey/splunk-network-tools/blob/master/src/bin/network_tools_app/simple_res...

Here is a helper library for a generic REST endpoint: https://gist.github.com/LukeMurphey/238004c8976804a8e79570d22721fd99

bnorthway_splun
Splunk Employee
Splunk Employee

could we get an example for exposing a POST endpoint to Splunk Web?

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...