<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How does Livestatus work in the integration of Nagios and Splunk? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-does-Livestatus-work-in-the-integration-of-Nagios-and-Splunk/m-p/206626#M60182</link>
    <description>&lt;P&gt;I don't know of any out of the box integrations with Livestatus so you'd be on your own writing a scripted or modular input to pull data in that way. I wouldn't re-invent the wheel here. Splunk as written the &lt;A href="https://splunkbase.splunk.com/app/2703/"&gt;Splunk Add-On for Nagios Core&lt;/A&gt;. It uses NDOUtils to pull data from Nagios and index in Splunk. You can view all the different &lt;A href="http://docs.splunk.com/Documentation/AddOns/latest/NagiosCore/Sourcetypes"&gt;sourcetypes that the app pulls in here&lt;/A&gt;. if you're interested in scheduled downtime look at the sourcetype &lt;B&gt;nagios:scheduleddowntime&lt;/B&gt;&lt;/P&gt;

&lt;P&gt;The requirement for NDOUtils is a little more heavy-weight than Livestatus but it will save you the trouble of having to build your own integration. A small price to pay in my opinion.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/AddOns/latest/NagiosCore/Hardwareandsoftwarerequirements"&gt;Here are the requirements&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you want to monitor NDOUtils data, you must:&lt;/P&gt;

&lt;P&gt;have NDOUtils installed on your Nagios instance&lt;BR /&gt;
 have an account with read privileges on the MySQL database of NDOUtils&lt;BR /&gt;
 have Splunk DB Connect v2 installed on the heavy forwarders responsible for data collection.&lt;/P&gt;</description>
    <pubDate>Fri, 10 Jun 2016 23:10:52 GMT</pubDate>
    <dc:creator>shaskell_splunk</dc:creator>
    <dc:date>2016-06-10T23:10:52Z</dc:date>
    <item>
      <title>How does Livestatus work in the integration of Nagios and Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-does-Livestatus-work-in-the-integration-of-Nagios-and-Splunk/m-p/206625#M60181</link>
      <description>&lt;P&gt;I'm running into incomplete documentation or irrelevant situations in trying to understand this, so I need help in straightening my definition of this environment. &lt;/P&gt;

&lt;P&gt;I have an instance of Nagios, an instance of Splunk, and a working Livestatus that provides a socket for which data from Nagios can be obtained. I understand that Livestatus can pull information from Nagios such as  &lt;CODE&gt;echo 'GET hosts'|unixcat /path/to/livestatus/live/socket&lt;/CODE&gt;. Another additional way of using Livestatus is creating files that contain custom queries which can have an organization of data as well as a filtering of data in order to provide items of relevance and importance and using &lt;CODE&gt;unixcat &amp;lt; queryName path/to/livestatus/live/socket&lt;/CODE&gt;. &lt;/P&gt;

&lt;P&gt;However, based on what I've seen Splunk do, it's simply pulling all the information in from Nagios, disregarding the Livestatus Queries. This begs the question of how do I get Splunk to receive filtered data from Nagios so as an example, receive data that a logging service is down and &lt;EM&gt;not&lt;/EM&gt; within scheduled down time? Once that data has been filtered, where on Splunk am I able to view the data of that query?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2016 15:27:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-does-Livestatus-work-in-the-integration-of-Nagios-and-Splunk/m-p/206625#M60181</guid>
      <dc:creator>TheHardHattedGe</dc:creator>
      <dc:date>2016-06-10T15:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: How does Livestatus work in the integration of Nagios and Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-does-Livestatus-work-in-the-integration-of-Nagios-and-Splunk/m-p/206626#M60182</link>
      <description>&lt;P&gt;I don't know of any out of the box integrations with Livestatus so you'd be on your own writing a scripted or modular input to pull data in that way. I wouldn't re-invent the wheel here. Splunk as written the &lt;A href="https://splunkbase.splunk.com/app/2703/"&gt;Splunk Add-On for Nagios Core&lt;/A&gt;. It uses NDOUtils to pull data from Nagios and index in Splunk. You can view all the different &lt;A href="http://docs.splunk.com/Documentation/AddOns/latest/NagiosCore/Sourcetypes"&gt;sourcetypes that the app pulls in here&lt;/A&gt;. if you're interested in scheduled downtime look at the sourcetype &lt;B&gt;nagios:scheduleddowntime&lt;/B&gt;&lt;/P&gt;

&lt;P&gt;The requirement for NDOUtils is a little more heavy-weight than Livestatus but it will save you the trouble of having to build your own integration. A small price to pay in my opinion.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/AddOns/latest/NagiosCore/Hardwareandsoftwarerequirements"&gt;Here are the requirements&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you want to monitor NDOUtils data, you must:&lt;/P&gt;

&lt;P&gt;have NDOUtils installed on your Nagios instance&lt;BR /&gt;
 have an account with read privileges on the MySQL database of NDOUtils&lt;BR /&gt;
 have Splunk DB Connect v2 installed on the heavy forwarders responsible for data collection.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2016 23:10:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-does-Livestatus-work-in-the-integration-of-Nagios-and-Splunk/m-p/206626#M60182</guid>
      <dc:creator>shaskell_splunk</dc:creator>
      <dc:date>2016-06-10T23:10:52Z</dc:date>
    </item>
  </channel>
</rss>

