All Apps and Add-ons

Can we analyze diag file with S.o.S by ourselves ?

sunrise
Contributor

We can set S.o.S on our UAT environment, but cannot set on production environment.
We want to analyze diag file getting from production environment to use S.o.S in UAT.
Can I do that ?
Can S.o.S allow us to analyze other environment diag file ?

1 Solution

hexx
Splunk Employee
Splunk Employee

The S.o.S app is not built to analyze data contained in diags, its searches are specifically targeted at live data in the Splunk internal indexes (_internal, _audit) and in its own index (sos).

View solution in original post

hexx
Splunk Employee
Splunk Employee

If you have attended a partner shadowing program with Splunk Support, you can reach out to the Support engineers that you worked with and request a copy of the UnDiag app, which does precisely what you want.

0 Karma

sunrise
Contributor

Actually, I'm working for the business partner of Splunk. I got the diag file from the end user to troubleshoot the issue. So I hope S.o.S enable to analyze at non-live data. .

0 Karma

hexx
Splunk Employee
Splunk Employee

Out of curiosity, what is the specific reason that prevents you from using the S.o.S app in your production environment?

hexx
Splunk Employee
Splunk Employee

The S.o.S app is not built to analyze data contained in diags, its searches are specifically targeted at live data in the Splunk internal indexes (_internal, _audit) and in its own index (sos).

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...