Getting Data In

Can a universal forwarder be restarted via REST API?

xiyangyang
Path Finder

Can UF be restart via REST API?
What other things can be done to UF via REST API?

harsmarvania57
Ultra Champion

Hi @xiyangyang,

Yes, you can restart UF via REST API (ref doc. http://docs.splunk.com/Documentation/Splunk/7.0.1/RESTREF/RESTsystem#server.2Fcontrol.2Frestart )

curl -k -u admin:changeme https://localhost:8089/services/server/control/restart -X POST

If you want to run above command from remote server then you need to change default password for admin user otherwise you will get below error.

<?xml version="1.0" encoding="UTF-8"?>
<response>
  <messages>
    <msg type="WARN">Remote login has been disabled for 'admin' with the default password. Either set the password, or override by changing the 'allowRemoteLogin' setting in your server.conf file.</msg>
  </messages>
</response>

I hope this helps.

Thanks,
Harshil

gcusello
SplunkTrust
SplunkTrust

Hi xiyangyang,
I don't know why you want to restart a UF using REST API, I think that the easiest way is a remote shell script.
Anyway you can find all the information about REST API features at http://dev.splunk.com/restapi .

Bye.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...