All Apps and Add-ons

Is there a documented way of archiving Tivoli Netcool polling data in Splunk?

jtrujillo
Path Finder

I have used other NMS systems to pipe to Splunk before for historical reporting. And I am sure that it can be done with Tivoli, but I am not sure where to start.

Right now, the use case is to index Interface statistics into splunk for reporting.

If anyone can help it would AWESOME.

0 Karma
1 Solution

paulstark
Path Finder

The Splunk for Tivoli Netcool App is designed to forward all data from the object server into Splunk. Polls, traps, syslog, CORBA, socket, TL1, and the myriad other probes that feed the object server can all be Splunk'd. After they have been processed, you can determine your retention policy and archive old data as outlined here http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Automatearchiving

In a nutshell you need to install the app on your Splunk platform, install the Splunk UF and Tech-Add ons onto your object server, and configure the flat file gateway (nco_g_file) to write the events.

View solution in original post

0 Karma

paulstark
Path Finder

The Splunk for Tivoli Netcool App is designed to forward all data from the object server into Splunk. Polls, traps, syslog, CORBA, socket, TL1, and the myriad other probes that feed the object server can all be Splunk'd. After they have been processed, you can determine your retention policy and archive old data as outlined here http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Automatearchiving

In a nutshell you need to install the app on your Splunk platform, install the Splunk UF and Tech-Add ons onto your object server, and configure the flat file gateway (nco_g_file) to write the events.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...