<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dell PowerScale Add-on for Splunk Configuration in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dell-PowerScale-Add-on-for-Splunk-Configuration-Are-the/m-p/633913#M78687</link>
    <description>&lt;P&gt;If the add-on provides the same data as syslog then you don't need both of them.&lt;/P&gt;</description>
    <pubDate>Thu, 09 Mar 2023 15:35:39 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2023-03-09T15:35:39Z</dc:date>
    <item>
      <title>Dell PowerScale Add-on for Splunk Configuration- Are the following syslog steps needed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dell-PowerScale-Add-on-for-Splunk-Configuration-Are-the/m-p/633833#M78675</link>
      <description>&lt;P&gt;If we are using the&amp;nbsp;Dell PowerScale Add-on for REST API calls, are the following syslog steps needed?&amp;nbsp; What is the purpose of syslog forwarding to a Splunk forwarder if the Add-on performs REST API calls to the Isilon cluster to pull this data?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;To enable forwarding syslog data in any Isilon Cluster version, perform the following steps:&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;Make following changes in file /etc/mcp/override/syslog.conf (copy from /etc/mcp/default/syslog.conf if not present):&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Put @&amp;lt;forwarders_ip_address&amp;gt; in front of the required log file and !* at the end of the syslog.conf file.&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Restart syslogd using this command - /etc/rc.d/syslogd restart.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;In some cases, syslog.conf file is already placed at /etc/mcp/override directory location but it is empty. In that case, just put the log file name and the forwarder ip in that file. Below is the content of sample syslog.conf:&lt;BR /&gt;auth.* @&amp;lt;forwarders_ip_address&amp;gt; !audit_config *.* @&amp;lt;forwarders_ip_address&amp;gt; !audit_protocol *.* @&amp;lt;forwarders_ip_address&amp;gt; !*&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Run the following commands to enable protocol, config and syslog auditing according to Isilon OneFS version:&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;For Dell Isilon cluster with oneFS version 9.x.x:&lt;BR /&gt;isi audit settings global modify --protocol-auditing-enabled Yes isi audit settings global modify --config-auditing-enabled Yes isi audit settings global modify --config-syslog-enabled Yes isi audit settings modify --syslog-forwarding-enabled Yes&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Thu, 09 Mar 2023 19:49:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dell-PowerScale-Add-on-for-Splunk-Configuration-Are-the/m-p/633833#M78675</guid>
      <dc:creator>rdraytheon</dc:creator>
      <dc:date>2023-03-09T19:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: Dell PowerScale Add-on for Splunk Configuration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dell-PowerScale-Add-on-for-Splunk-Configuration-Are-the/m-p/633913#M78687</link>
      <description>&lt;P&gt;If the add-on provides the same data as syslog then you don't need both of them.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 15:35:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dell-PowerScale-Add-on-for-Splunk-Configuration-Are-the/m-p/633913#M78687</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-03-09T15:35:39Z</dc:date>
    </item>
  </channel>
</rss>

