Developing with Splunk's REST API 8.0

Developing with Splunk's REST API 8.0

Upcoming Classes

Online

Instructor-led online training

Location Jul 2020 Aug 2020 Sep 2020 Oct 2020 Nov 2020 Dec 2020 Jan 2021
AMER Eastern Time - Virtual Aug 10 – Aug 11
Sep 21 – Sep 22
Oct 26 – Oct 27
EMEA UK Time - Virtual Aug 17 – Aug 18
Sep 14 – Sep 15
Oct 12 – Oct 13
AMER Pacific Time - Virtual Sep 10 – Sep 11

Summary

This nine hour course teaches you to use the Splunk REST API to accomplish tasks on a Splunk server. In this course, you will use curl and Python to send requests to Splunk REST endpoints and will learn how to parse the results. The course will show you how to create a variety of objects in Splunk, how to work with and apply security to Splunk objects, issue different types of searches, and ingest data.

Description

  • Introduction to the Splunk REST API
  • Namespaces and Object Management
  • Parsing Output
  • Oneshot Searching
  • Normal and Export Searching
  • Advanced Searching and Job Management
  • Working with Indexes
  • Using the HTTP Event Collector
  • Course Wrap-up (includes the SPL rest command

Duration

2 Days

Objectives

Module 1 – Introduction to the Splunk REST API

  • Use the proper case in searches
  • Introduce the Splunk development environment and its REST endpoints
  • Know to which Splunk server you should be connected to accomplish a desired task
  • Authenticate with a Splunk server, with and without a session

Module 2 – Namespaces and Object Management

  • Understand how a namespace affects access to objects
  • Use the servicesNS node and a namespace to access objects
  • Understand how the sharing level and access control lists affect access to objects
  • Modify the sharing level and the permissions on an object

Module 3 – Parsing Output

  • Understand the general structure of Atom-based output
  • Format Atom-based JSON output

Module 4 – Oneshot Searching

  • Review search language syntax and search best practices
  • Execute a oneshot search
  • Execute an export search
  • Get search results

Module 5–Normal and Export Searching 

  • Identify types of searches
  • Create normal and export searches
  • Get search results, search job status and other search job properties

Module 6 – Advanced Searching and Job Management

  • Executing a real time search
  • Working with large results sets
  • Working with saved searches
  • Managing search jobs

Module 7 – Working with the kvstore

  • Define what is a KV Store
  • Define collections and records
  • Perform CRUD operations on collections and records

Module 8 – Using the HTTP Event Collector (HEC)

  • Create and use HEC tokens
  • Input data using HEC endpoints
  • Get indexer event acknowledgements

Module 9– Using the rest Command

  • Use the SPL rest command
  • Final notes

 

Onsite Training

For groups of three or more

Request Quote

Public Training

AMER Eastern Time - Virtual

EMEA UK Time - Virtual

AMER Pacific Time - Virtual


Don't see a date that works for you?

Request Class