Developing with Splunk's REST API 8.1

Developing with Splunk's REST API 8.1

Upcoming Classes

Online

Instructor-led online training

Location Jun 2021 Jul 2021 Aug 2021 Sep 2021 Oct 2021 Nov 2021 Dec 2021
AMER Pacific Time - Virtual Jun 21 – Jun 22
Aug 23 – Aug 24
Oct 11 – Oct 12
EMEA UK Time - Virtual Jul 12 – Jul 13
Aug 9 – Aug 10
Sep 13 – Sep 14
Oct 11 – Oct 12
AMER Eastern Time - Virtual Jul 12 – Jul 13
Aug 9 – Aug 10
Sep 13 – Sep 14
Sep 27 – Sep 28
Oct 25 – Oct 26

Germany

Location Jun 2021 Jul 2021 Aug 2021 Sep 2021 Oct 2021 Nov 2021 Dec 2021
Munich Germany (Arrow) Jul 2

Summary

This nine hour course teaches you how to use the Splunk REST API to accomplish tasks interacting with Splunk servers. In this course, you will use curl and Python to send requests to Splunk REST endpoints and will learn how to parse and use the results. The course will show you how to create a variety of objects in Splunk, how to change properties, work with and apply security to Splunk objects, run different types of searches and parse its results, ingest data using the HTTP Event Collector and manipulate collections and KV Stores.

Description

  • Introduction to the Splunk REST API
  • Namespaces and Object Management
  • Parsing Output
  • Oneshot Searching
  • Normal and Export Searching
  • Advanced Searching and Job Management
  • Working with KV Stores
  • Using the HTTP Event Collector

Duration

2 Days

Objectives

Module 1 – Introduction to the Splunk REST API

  • Use the proper case in searches
  • Introduce the Splunk development environment and its REST endpoints
  • Know to which Splunk server you should be connected to accomplish a desired task
  • Authenticate with a Splunk server, with and without a session

Module 2 – Namespaces and Object Management

  • Understand general CRUD with the REST API
  • Understand how a namespace affects access to objects
  • Use the servicesNS node and a namespace to access objects
  • Understand how the sharing level and access control lists affect access to objects
  • Modify the sharing level and the permissions on an object
  • Using the rest command

Module 3 – Parsing Output

  • Understand the general structure of Atom-based output
  • Format Atom-based JSON output
  • Write code that uses the API and parse responses

Module 4 – Oneshot Searches

  • Review search language syntax and search best practices
  • Execute a oneshot search
  • Execute an export search
  • Get search results

Module 5–Normal and Export Searching 

  • Identify types of searches
  • Create normal and export searches
  • Get:
  • Search results
  • Search job status and other search job properties

Module 6 – Advanced Searching and Job Management

  • Executing a real time search
  • Working with large results sets
  • Working with saved searches
  • Managing search jobs

Module 7 – Working with the KV Store

  • Define the function of a KV Store
  • Define collections and records
  • Perform CRUD operations on collections and records

Module 8 – Using the HTTP Event Collector (HEC)

  • Create and use HEC tokens
  • Input data using HEC endpoints
  • Get indexer event acknowledgements

 

Prerequisites

Classes:

Splunk Fundamentals 1

Splunk Fundamentals 2

Splunk Data Administration or Splunk Cloud Administration is recommended but not required

Advanced Searching and Reporting recommended but not required

Software development or scripting experience

 

Onsite Training

For groups of three or more

Request Quote

Public Training

AMER Pacific Time - Virtual

Munich

  • Confirmed
    9:00 AM - 5:00 PM
    $ 1000.00 USD

EMEA UK Time - Virtual

AMER Eastern Time - Virtual


Don't see a date that works for you?

Request Class