All Apps and Add-ons
Highlighted

How do I configure Splunk App for ServiceNow to read from a custom index?

Communicator

I altered the Splunk Add-on for ServiceNow to put data in index=snow instead of index=main.
How do I configure Splunk App for ServiceNow to search index=snow ?

0 Karma
Highlighted

Re: How do I configure Splunk App for ServiceNow to read from a custom index?

Contributor

Hi Davebo,

Is your add-on and app on the same Splunk instance ? If so , then do not run set-up to configure the add-on to enable the inputs , instead setup the servicenow App to collect data directly which will enable the inputs on app and they get saved in servicenowapp/local/inputs .conf. Then change the index=main to index=snow in inputs.conf, followed by restart of splunk .

refer to this page - http://docs.splunk.com/Documentation/ServiceNow/4.0.3/Install/Setuptheapp

0 Karma
Highlighted

Re: How do I configure Splunk App for ServiceNow to read from a custom index?

Communicator

Do I need to install the TA if it is all on one host?

0 Karma
Highlighted

Re: How do I configure Splunk App for ServiceNow to read from a custom index?

Communicator

I don't see servicenowapp/local/inputs .conf after configuring. There is SplunkTAsnow/local/inputs.conf . Is that what you mean?

0 Karma
Highlighted

Re: How do I configure Splunk App for ServiceNow to read from a custom index?

Communicator

If I understand this correctly. It is SplunkTAsnow/local/inputs.conf
and it needs to be set up prior to configuring the connection via the UI:

[snow]
index = snow
since_when = 2017-01-01 00:00:00

It also appears that this index has to be set as "allowed" and "search by default" for the role that will be accessing this app as the index is not specified in a macro.

0 Karma
Highlighted

Re: How do I configure Splunk App for ServiceNow to read from a custom index?

Communicator

Why am I getting errors about a non-existent index?
index=snowcmdbcilistindex

0 Karma
Highlighted

Re: How do I configure Splunk App for ServiceNow to read from a custom index?

Contributor

Is your Splunk setup standalone or clustered ?

if you're going to install the TA and App on the same instance then.. you just need to install the TA first , but skip the configure step. and then configure the app to pull data from ServiceNow rather.

But since you've already configured the TA with inputs and updated the inputs.conf with index=snow, then it has to be allowed to search.

servicenow TA creates some indexes as part of the installation, You should add these indexes to your main indexes.conf file with reference to Primary volume -

snow is index I created. the rest were created by the TA and would through errors, for not referencing the primary volume. So I added it to the master indexes. conf file.

example -

[snow]
homePath = volume:primary/snow/db
coldPath = volume:primary/snow/colddb
thawedPath = $SPLUNK_DB/snow/thaweddb
maxTotalDataSizeMB = 750000
frozenTimePeriodInSecs = 31536000

[snowsysusergrouplistindex]
homePath = volume:primary/snow
sysusergrouplistindex/db
coldPath = volume:primary/snowsysusergrouplistindex/colddb
thawedPath = $SPLUNK
DB/snowsysusergrouplist_index/thaweddb
maxTotalDataSizeMB = 750000
frozenTimePeriodInSecs = 31536000

[snowcmdbcilistindex]
homePath = volume:primary/snowcmdbcilistindex/db
coldPath = volume:primary/snowcmdbcilistindex/colddb
thawedPath = $SPLUNKDB/snowcmdbcilist_index/thaweddb
maxTotalDataSizeMB = 750000
frozenTimePeriodInSecs = 31536000

[snowincidentstateindex]
homePath = volume:primary/snow
incidentstateindex/db
coldPath = volume:primary/snowincidentstateindex/colddb
thawedPath = $SPLUNK
DB/snowincidentstate_index/thaweddb
maxTotalDataSizeMB = 750000
frozenTimePeriodInSecs = 31536000

0 Karma