Developing with Splunk's REST API (DSRAPI)

 

Résumé du cours

This nine hour course is for developers who want to use the Splunk REST API to interact with Splunk servers. In this course, you will use curl and Python to send requests to Splunk REST endpoints and learn how to parse and use the results. Create a variety of objects in Splunk, learn how to change properties, work with and apply security to Splunk objects, run different types of searches and parse its results, ingest data using the HTTP Event Collector and manipulate collections and KV Stores.

Please note that this class may run over two days, with 4.5 hour sessions each day, with a total of nine hours of content.

A qui s'adresse cette formation

This 9-hour course is for developers who want to use the Splunk REST API to interact with Splunk servers.

Certifications

Cette formation prépare à la/aux certifications:

Pré-requis

To be successful, students should have a solid understanding of the following:

  • Splunk Fundamentals 1 and 2 (Retired)

Or the following single-subject courses:

Students should also understand the following courses:

Objectifs

  • Introduction to the Splunk REST API
  • Namespaces and Object Management
  • Parsing Output
  • Oneshot Searching
  • Normal and Export Searching
  • Advanced Searching and Job Management
  • Working with KV Stores
  • Using the HTTP Event Collector (HEC)

Outline: Developing with Splunk's REST API (DSRAPI)

Module 1 – Introduction to the Splunk REST API

  • Introduce the Splunk development environment and its REST endpoints
  • Connect to the appropriate Splunk server to accomplish a desired task
  • Authenticate with a Splunk server, with and without a session

Module 2 – Namespaces and Object Management

  • Understand general CRUD with the REST API
  • Identify how a namespace affects access to objects
  • Use the servicesNS node and a namespace to access objects
  • Understand how the sharing level and access control lists affect access to objects
  • Modify the sharing level and the permissions on an object

Module 3 – Parsing Output

  • Understand the general structure of Atom-based output
  • Format Atom-based JSON output
  • Write code that uses the API and parse responses

Module 4 – Oneshot Searches

  • Review search language syntax and search best practices
  • Execute one shot searches
  • Get search results

Module 5 – Normal and Export Searches

  • Identify types of searches
  • Execute normal and export searches
  • Get search results, job status and search job properties.

Module 6 – Advanced Searching and Job Management

  • Execute a real time search
  • Work with saved searches
  • Manage search jobs

Module 7 – Working with the KV Store

  • Define the function of a KV Store
  • Define collections and records
  • Perform CRUD operations on collections and records

Module 8 – Using the HTTP Event Collector (HEC)

  • Create and use HEC tokens
  • Input data using HEC endpoints
  • Get indexer event acknowledgements

Module 9 – Useful Admin REST APIs[list] [*] Get system information [*] Manage Splunk configuration files [*] Manage Indexes[/list]

Module 10 – Custom REST Endpoints[list] [*] Extending the Splunk REST API [*] Publish your own endpoints [*] Using custom REST API endpoints[/list]

Prix & Delivery methods

Formation en ligne

Durée
9 heures

Prix
  • Online Training : CAD 1 270,–
  • Online Training : US$ 1 000,–
  • Splunk Training Credits : 100 SPC
Formation en salle équipée

Durée
9 heures

Prix
  • Canada : CAD 1 270,–
  • Splunk Training Credits : 100 SPC

Cliquez sur le nom de la ville ou sur « Formation en ligne » pour réserver Agenda

This is an Instructor-Led Classroom course
Date garantie :   Fast Lane s’engage à mettre en œuvre les formations garanties quelque soit le nombre de participants, en dehors des cas de force majeurs ou d’événements exceptionnels, comme un accident ou un maladie de l’instructeur.
Instructor-led Online Training :   Cours en ligne avec instructeur
*   This class is delivered by a partner.

Etats-Unis

garanti ! Formation en ligne 09:00 US/Eastern Cette formation est réalisée par un partenaire S'inscrire
Formation en ligne 09:00 US/Pacific Cette formation est réalisée par un partenaire S'inscrire