All Apps and Add-ons

Can we analyze diag file with S.o.S by ourselves ?

sunrise
Contributor

We can set S.o.S on our UAT environment, but cannot set on production environment.
We want to analyze diag file getting from production environment to use S.o.S in UAT.
Can I do that ?
Can S.o.S allow us to analyze other environment diag file ?

1 Solution

hexx
Splunk Employee
Splunk Employee

The S.o.S app is not built to analyze data contained in diags, its searches are specifically targeted at live data in the Splunk internal indexes (_internal, _audit) and in its own index (sos).

View solution in original post

hexx
Splunk Employee
Splunk Employee

If you have attended a partner shadowing program with Splunk Support, you can reach out to the Support engineers that you worked with and request a copy of the UnDiag app, which does precisely what you want.

0 Karma

sunrise
Contributor

Actually, I'm working for the business partner of Splunk. I got the diag file from the end user to troubleshoot the issue. So I hope S.o.S enable to analyze at non-live data. .

0 Karma

hexx
Splunk Employee
Splunk Employee

Out of curiosity, what is the specific reason that prevents you from using the S.o.S app in your production environment?

hexx
Splunk Employee
Splunk Employee

The S.o.S app is not built to analyze data contained in diags, its searches are specifically targeted at live data in the Splunk internal indexes (_internal, _audit) and in its own index (sos).

Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...