All Apps and Add-ons

How does the SA_Syslog_collection app gather stats from UF's?

rpquinlan
Path Finder

The app says that it needs to be installed on the indexers and the search heads, but how is the app to gather information (and perform the ' netstat -stu ' command mentioned in the docu) from the UF's without it being installed there as well?

I must be missing something simple.

Tags (1)
0 Karma
1 Solution

nickhills
Ultra Champion

Having a quick look at the inputs, its been designed to run netstat on the indexers, not the forwarders.

If my comment helps, please give it a thumbs up!

View solution in original post

nickhills
Ultra Champion

Having a quick look at the inputs, its been designed to run netstat on the indexers, not the forwarders.

If my comment helps, please give it a thumbs up!

rpquinlan
Path Finder

That's how it appears to me as well, though the app's documentation talks about using syslog-ng on UF's and how it can gather additional metrics on the UF's.. Bummer.

0 Karma

nickhills
Ultra Champion

I guess you cold configure the UF app to run the same script on the forwarders too?

If my comment helps, please give it a thumbs up!
0 Karma

rpquinlan
Path Finder

Hmmm.. have a CRON job run the script and output it to a file that the UF watches... That is an idea!

0 Karma

nickhills
Ultra Champion

I meant as a scripted input - then you can manage it from your deployment server, without having to resort to cron.

If my comment helps, please give it a thumbs up!
0 Karma

rpquinlan
Path Finder

Got it! That's a better idea, working on that now.

0 Karma

rpquinlan
Path Finder

Brilliant. That's working, thank you for the suggestion!
Note for anyone else who may have a Windows deployment server and a *nix UF - you'll have to check/change the file permissions / owner on the .sh file after deployment,

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...