# Logstash http\_poller pulling data recursively

**URL:** <https://discuss.elastic.co/t/logstash-http-poller-pulling-data-recursively/345742>\
**Category:** Logstash\
**Created:** [October 25, 2023, 2:34pm UTC](https://discuss.elastic.co/t/logstash-http-poller-pulling-data-recursively/345742 "2023-10-25T14:34:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ankita\_Pachauri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankita_pachauri/32/61469_2.png) [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Post date:** [October 25, 2023, 2:34pm UTC](https://discuss.elastic.co/t/logstash-http-poller-pulling-data-recursively/345742/1 "2023-10-25T14:34:52Z")

</div>

Hi All,

I have to use logstash to pull metric data using ManageEngine AppManager's REST API. The task has to be done in two phases, the first phase would be to pull all objects/resource ids under a specific group using a URI endpoint like below.

https://[HOST]:[PORT]/AppManager/json/ListMonitorGroups?apikey=[API Key]&groupId=10000035

Next, task is that based on all the resource id's returned by the command above, loop over all the resource ids using a different URL endpoint like the one mentioned below.

https://[HOST]:[PORT]/AppManager/xml/ListMonitor?apikey=[API key]&resourceid=[Resourceid]

[Resourceid] will get replaced by resource id one by one and API call would be made.

I can use the http\_poller to run the first phase and save the resource ids in a variable, however not sure how to achieve the second part.

Can someone help me with ideas on getting this done.

//Ankita Pachauri

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 27, 2023, 12:48am UTC](https://discuss.elastic.co/t/logstash-http-poller-pulling-data-recursively/345742/2 "2023-10-27T00:48:44Z")

</div>

If the resource ids are in an array then use a split filter to have one event per resource id and then use an http filter to do the second API call.

---

<div class="post-metadata">

**Author:** ![Ankita\_Pachauri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankita_pachauri/32/61469_2.png) [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Post date:** [October 27, 2023, 4:17pm UTC](https://discuss.elastic.co/t/logstash-http-poller-pulling-data-recursively/345742/3 "2023-10-27T16:17:09Z")

</div>

Thanks Badger, the resource ids are indeed in an array and split can be used. However, can you please share the sample configuration on how to use http filter recursively for multiple calls?

//Ankita Pachauri

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 27, 2023, 5:28pm UTC](https://discuss.elastic.co/t/logstash-http-poller-pulling-data-recursively/345742/4 "2023-10-27T17:28:33Z")

</div>

I do not understand why you need recursion. The idea of using split is that each event has a single resource id so you can use a field reference in the http filter.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 24, 2023, 5:29pm UTC](https://discuss.elastic.co/t/logstash-http-poller-pulling-data-recursively/345742/5 "2023-11-24T17:29:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
