<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get NetApp logs into Splunk in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-NetApp-logs-into-Splunk/m-p/60938#M3674</link>
    <description>&lt;P&gt;For details on how to get logs, performance and configuration data from NetApp ONTAP environment, please refer to Splunk App for NetApp Data ONTAP docs:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/NetApp/2.0/DeployNetapp/Configuredatacollection"&gt;http://docs.splunk.com/Documentation/NetApp/2.0/DeployNetapp/Configuredatacollection&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 15 Feb 2014 00:14:31 GMT</pubDate>
    <dc:creator>sudovicic_splun</dc:creator>
    <dc:date>2014-02-15T00:14:31Z</dc:date>
    <item>
      <title>How to get NetApp logs into Splunk</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-NetApp-logs-into-Splunk/m-p/60935#M3671</link>
      <description>&lt;P&gt;Installed Splunk within environment, and wanted to forward all NetApp logs into SPLUNK Indexer. Current set up is Splunk Search head and Indexer on same box, one syslog server that is being indexed. Would like a step by step to forward logs from NetApp to Splunk.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2013 21:28:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-NetApp-logs-into-Splunk/m-p/60935#M3671</guid>
      <dc:creator>blasighb</dc:creator>
      <dc:date>2013-09-11T21:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to get NetApp logs into Splunk</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-NetApp-logs-into-Splunk/m-p/60936#M3672</link>
      <description>&lt;P&gt;There is a documentation tab on the App website.  If you run into issues after following those steps feel free to post a question.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://apps.splunk.com/app/1293"&gt;http://apps.splunk.com/app/1293&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2013 22:12:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-NetApp-logs-into-Splunk/m-p/60936#M3672</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2013-09-11T22:12:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to get NetApp logs into Splunk</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-NetApp-logs-into-Splunk/m-p/60937#M3673</link>
      <description>&lt;P&gt;What @sdaniels said, but if the only thing you are interested in are the actual system logs (and not performance or configuration data, which the app provides in addition), then you can certainly do syslog forwarding. On NetApp 7-mode, it works exactly like any unix, i.e. 'man syslogd.conf'. Here's a blog post with some instructions: &lt;A href="http://networkadminkb.com/KB/a455/how-to-configure-a-netapp-fas-to-forward-syslog-messages.aspx"&gt;http://networkadminkb.com/KB/a455/how-to-configure-a-netapp-fas-to-forward-syslog-messages.aspx&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Cluster-mode is different. You would use the 'event' command while logged into a command shell. ONTAP 8.1 reference guide link [may require login to view]: &lt;A href="https://library.netapp.com/ecmdocs/ECMP1120736/html/event/destination/modify.html"&gt;https://library.netapp.com/ecmdocs/ECMP1120736/html/event/destination/modify.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2013 05:05:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-NetApp-logs-into-Splunk/m-p/60937#M3673</guid>
      <dc:creator>halr9000</dc:creator>
      <dc:date>2013-09-12T05:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to get NetApp logs into Splunk</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-NetApp-logs-into-Splunk/m-p/60938#M3674</link>
      <description>&lt;P&gt;For details on how to get logs, performance and configuration data from NetApp ONTAP environment, please refer to Splunk App for NetApp Data ONTAP docs:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/NetApp/2.0/DeployNetapp/Configuredatacollection"&gt;http://docs.splunk.com/Documentation/NetApp/2.0/DeployNetapp/Configuredatacollection&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Feb 2014 00:14:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-NetApp-logs-into-Splunk/m-p/60938#M3674</guid>
      <dc:creator>sudovicic_splun</dc:creator>
      <dc:date>2014-02-15T00:14:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to get NetApp logs into Splunk</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-NetApp-logs-into-Splunk/m-p/60939#M3675</link>
      <description>&lt;P&gt;Hi i had an issue with the NetApp plugin, i've already configured and installed and also add the cluster mode array with the IP address and credentials validated. Also i run the Scheduler, but when i go to the "Proactive Monitoring" and then for example to the "Cluster View" i'm getting the following message "Search query is not fully resolved.", and nothing is displayed. Could someone help me out with this since i'd like to try Splunk to monitor our Filers from NetApp.&lt;/P&gt;

&lt;P&gt;Thanks in advance,&lt;/P&gt;

&lt;P&gt;Best regards to all&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2014 16:44:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-NetApp-logs-into-Splunk/m-p/60939#M3675</guid>
      <dc:creator>gertux</dc:creator>
      <dc:date>2014-02-19T16:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to get NetApp logs into Splunk</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-NetApp-logs-into-Splunk/m-p/60940#M3676</link>
      <description>&lt;P&gt;There could be a couple different causes to this issue.  One is that the tsidx searches did not finish populating their indexes before the page was loaded.  This issue will resolve itself over time.&lt;/P&gt;

&lt;P&gt;First, it might be helpful to check that you're getting data.  By default, data goes into &lt;CODE&gt;index=ontap&lt;/CODE&gt;.  If this index is empty, then there's a problem with your configuration.  Check that your data collection node is configured as a forwarder and sending data to your indexer.  If you're not seeing data in &lt;CODE&gt;index=_internal&lt;/CODE&gt; from the data collection node host, then there's a connection problem that needs resolution.&lt;/P&gt;

&lt;P&gt;If you're still seeing the same issues, check &lt;CODE&gt;index=_internal sourcetype=splunk_ta_ontap_api* OR sourcetype=hydra* ERROR&lt;/CODE&gt; for any errors during collection.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2014 20:01:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-NetApp-logs-into-Splunk/m-p/60940#M3676</guid>
      <dc:creator>bboe</dc:creator>
      <dc:date>2014-02-20T20:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to get NetApp logs into Splunk</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-NetApp-logs-into-Splunk/m-p/60941#M3677</link>
      <description>&lt;P&gt;I am facing a similar issue where I am not able to see any data. Just wanted to confirm on the settings that I did.&lt;/P&gt;

&lt;P&gt;I have a Splunk server which is configured as a SearchHead and Indexer. Installed the Netapp App on that.&lt;BR /&gt;
On this server, I added a OntapServer by clicking on the "Add Ontap Collection" button. Is that fine. &lt;/P&gt;

&lt;P&gt;I have not setup any Data Collection Node. Is it mandatory to set up one?&lt;/P&gt;

&lt;P&gt;I don't see anything in index=_internal host=someHost.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2015 16:43:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-get-NetApp-logs-into-Splunk/m-p/60941#M3677</guid>
      <dc:creator>hitesh_kanchan</dc:creator>
      <dc:date>2015-06-11T16:43:53Z</dc:date>
    </item>
  </channel>
</rss>

