Splunk Search

Need a help with posting data using Rest API's from one Splunk to another using webhook and HEC

satyaallaparthi
Communicator

Hello,

I have my own Splunk where I installed SPLUNK ES
and I just got the Search head access from somebody's SPLUNK where I can Create alerts ( no backend Access). Just to see data and create Knowledge objects.

I want to create an alert in outside Splunk and in alert actions I want to use WEBHOOK action and need to give the Splunk rest API to post the alert data into my Search head where I installed ES as a notable events using HEC.

how should I post the alert data using rest api from another Splunk where I got the only UI access to my SPLUNK ES?
how to create write API link in webhook action using my ES HEC in another splunk?

Thanks in advance..any help would be appreciated..

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...