Splunk Enterprise

Which is better when connect Splunk from custom rest endpoint file?

datphamtat
Explorer

Hi guy,

I am using Splunk UI to develop new app on the Splunk

My app has components:

  • Setup page: let people provide some configuration such as Splunk Token, Splunk HEC token, Proxy config
  • App component:
  • Custom Rest endpoint (python)

 

From the app comment, I will make some calls to the custom rest endpoint to get / process data.

On the setup page, I save all configurations into KV-store, to re-use

So my question is:

- How custom rest endpoint script (python file) can get information from KV-store, as you know, with python SDK, need a credential to authorize with Splunk. Have any way to connect Splunk from the custom rest endpoint script without authen?

- Which place is better to save credentials or configurations in Splunk? kv sore? storage password or config file 

- If does not any way to authen with Splunk from Custom rest endpoint without credentials, how can pass credentials to rest endpoint? Enter credential into config file? or attach credentials in the param request when we call the rest endpoint?

 

Thank!
P/s: The first time I see a big platform have many version/options to develop, It make develop is confused ( Splunkjs, Splunk SDK, Splunk UI ...)

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...