All Apps and Add-ons

Anyone have an SCCM app that works with Splunk 7.x?

heatonjl
Engager

I've downloaded the 3 yr old app, that says it works for 6.2, but I can't seem to get it working with Splunk 7. Anything that anyone can offer would be appreciated.

Tags (2)

pl2345
Path Finder

I posted an answer in another page that may help. I rewrote all the DB queries so it's all native to the SCCM app.

Re: Splunk community NEEDS an answer for getting S... - Splunk Community

0 Karma

pl2345
Path Finder

I recently got the SCCM app working with Splunk 7.1.3 and DBConnect 3.2.0. I used the SCCM app as a template and modified as necessary, granted it took me a few months to get everything working right:

  1. I used SQL Server manager to create new views based on the dbconnect queries in the package. This was mainly because I could input them into dbconnect and run them, but when I went to save them I'd receive an error.

  2. I rewrote most of the dashboards and pages to work with the new queries and had success with them, The only issue so far is that because the rising column doesn't work with the queries, some of the time pickers don't work, or I had to get creative with time sorting.

  3. After that it was just setting up alerts for the SCCM daily/weekly/monthly recommended monitoring.

Let me know if you need more specific pointers on getting it working.

nick405060
Motivator

I don't, but I wish Splunk was willing to put even a little effort into addressing this problem

nick405060
Motivator

+1..... trying to get it to work with 6.3. It installs but there is no Settings/config for it in the interface

0 Karma

TobiasBoone
Communicator

I need to be able to leverage splunk to confirm machines that are on the network are accounted for in sccm... and as sccm is notorious for not always checking in correctly I do't know another way. Also looking for an updated SCCM connector for splunk 7.x

0 Karma

Hemnaath
Motivator

Hi TobiasBoone, We are planning to install the SCCM app in our organization and we are using 6.6.1 splunk Enterprise version, but I am not finding any good documentation which can explain how to configure the SCCM app to pull the information in splunk. So if you can share me the procedure or steps to configure this, it will be really great help.

thanks in advance.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...