Your on-premises or cloud Splunk instance can pull data from the Axero REST API Overview, so you can search, monitor, and examine Axero data there, such as user activity logs.
1. Open your Splunk account.
2. Click "Find More Apps".
3. Search for and install the Splunk Add-on Builder. (Splunkbase link: https://apps.splunk.com/app/2962/)
4. Once installed, launch the Splunk Add-on Builder and select "New Add-on".
5. Name your add-on as desired, then click "Create".
6. Click "Configure Data Collection".
7. Click "New Input".
8. Select "Modular input using a REST API".
9. Name your source type and input as desired, then click "Next".
10. Enter the appropriate REST URL from our REST API Overview, then click "Test".
Example request:
GET REST API: Get User Activity
11. Expand "Event extraction settings" and enter the JSON path to the array in the payload to use for breaking the data into individual events for Splunk. Then click "Finish".
In the example request, this would be $.ResponseData:
12. Go back to your Splunk homepage, navigate to the newly created add-on in your apps, and click "Create New Input".
13. Name your input, select a time interval for the input in seconds, and select the desired index. Then click "Add".
14. Navigate back to the Splunk add-on builder from the homepage and click on the add-on you built.
15. Click "Extracted Fields".
16. Click "Assisted Extraction".
Note if "Assisted Extraction" is greyed out, make sure you completed steps 12-13 before starting steps 14-15.
17. Select "JSON".
18. Click "Save".
Splunk now pulls Axero data on the interval you set.
is requesting access to a wiki that you have locked: https://my.axerosolutions.com/spaces/5/axero-documentation/wiki/view/88056/splunk-integration-setup
Your session has expired. You are being logged out.