Skip to main content
REST Profiler for Splunk app icon

REST Profiler for Splunk

REST Profiler for Splunk turns any HTTP API into a Splunk alert action. Define reusable, fully-featured REST request profiles once, authentication, proxy, retries, validation, encrypted secrets and fire them automatically when alerts trigger, including sending the triggering results themselves in JSON, XML, form, query-parameter, or templated format.

Built by majid ershadi
splunk product badge
screenshot
screenshot
screenshot
screenshot

Default Version 1.0.0
June 16, 2026
Compatibility
Splunk Enterprise, Splunk Cloud
Platform Version: 10.4, 10.3, 10.2, 10.1, 10.0
Rating

5

(2)

Log in to rate this app
Support
Developer Supported
Most HTTP alert actions make you retype an endpoint, headers, and credentials into every alert — in plain text. REST Profiler takes a different approach: requests are profiles managed once on a dedicated configuration page with all secrets encrypted in Splunk secure storage, then reused everywhere. Typical use cases: - Notify through any SMS or messaging gateway— call Twilio, Kavenegar, or any HTTP SMS API with the alert's fields templated into the request body. - Exchange security incidents (IODEF— deliver RFC 7970 IODEF XML incident documents to a CSIRT/CERT endpoint, with mutual-TLS client-certificate authentication where required. - Create and update tickets— open incidents in ServiceNow, Jira, or any REST-capable ITSM tool, one ticket per triggering result row. - Trigger SOAR / automation platforms— kick off playbooks via webhook with validated delivery (expected status codes, response-content checks) and automatic retry with exponential backoff. - Send chat notifications— post to Slack, Microsoft Teams, Mattermost, or any incoming-webhook endpoint. - Integrate with internal systems— reach services behind a corporate proxy (HTTP/HTTPS/SOCKS5, with separate proxy credentials), including self-signed or private-CA TLS endpoints. Feature highlights: - Reusable profiles: create, edit, clone, delete from a dedicated UI. - Exact request Preview(secrets masked) and live Test send per profile. - All HTTP methods: GET, POST, PUT, PATCH, DELETE, HEAD, OPTIONS. - Authentication: none, HTTP Basic, token/bearer (custom header and prefix), and mutual TLS* (client certificate, optional encrypted private-key passphrase). - Secrets (passwords, tokens, certificates, passphrases) encrypted in Splunk secure storage; never shown in previews or logs. - Per-row result delivery: send each triggering result as a JSON, XML, or form-urlencoded body, as URL query parameters, or through a custom `$field$` template in the body and URL. - Reliability controls per profile: request timeout, retry with exponential backoff (connection errors, optionally HTTP 5xx/429), rate limiting between requests, and response validation (expected status codes, required body content). - Proxy support per profile: HTTP, HTTPS, or SOCKS5, with a separate proxy-authentication option. - `| restprofilersend` search command for ad-hoc and scheduled execution. - Monitoring dashboard, configurable logging level, and a built-in Search view.

Categories

IT Operations, DevOps

Created By

majid ershadi

Type

app

Downloads

22

Resources

Log in to report this app listing