Course Overview
This 9-hour course is for developers who want to use the Splunk REST API to interact with Splunk servers. In this course, use curl and Python to send requests to Splunk REST endpoints and learn how to parse and use the results. Create a variety of objects in Splunk, learn how to change properties, work with and apply security to Splunk objects, run different types of searches and parse its results, ingest data using the HTTP Event Collector and manipulate collections and KV Stores.
Please note that this class may run over two days, with 4.5 hour sessions each day, with a total of nine hours of content.
Who should attend
This 9-hour course is for developers who want to use the Splunk REST API to interact with Splunk servers.
Prerequisites
To be successful, students should have a solid understanding of the following:
- Splunk Fundamentals 1 and 2 (Retired)
Or the following single-subject courses:
- What is Splunk? (Retired)
- Intro to Splunk (ITS)
- Using Fields (Free) (SUFF) or Using Fields (SUF)
- Working with Time (WWT)
- Statistical Processing (SSP)
- Search Under the Hood (SUH)
- Intro to Knowledge Objects (IKO)
Students should also understand the following courses:
- Splunk Enterprise Data Administration (SEDA) (Recommended)
Course Objectives
- Introduction to the Splunk REST API
- Namespaces and Object Management
- Parsing Output
- Oneshot Searching
- Normal and Export Searching
- Advanced Searching and Job Management
- Working with KV Stores
- Using the HTTP Event Collector (HEC)