Hi all,

I’m somewhat new to working with APIs and scom, but I’ve been trying to use the Web API to pull some data from splunk into scom. I’ve been using the below guide which is good but I have a few questions I’m hoping someone can help me with.

  1. Why is my splunk search a POST instead of a GET according to the documentation? I’m “getting” information from splunk, not posting any data to it.
  2. Why when i do output_mode to json, it doesn’t auto-generate the column names? Without these, I get [object],[object], etc which says to me these would be columns, but when I add the json piece, it gives me an error that splunk returned unexpected data
  3. Any common gotchas trying to do this kind of API call with splunk? Right now I’m running what should be a basic search


Adam answered