All Apps and Add-ons

Is there any documentation available for the Broken Hosts App for Splunk?

a212830
Champion

Hi,

Looking at the Broken Hosts App for Splunk, but there isn't any real documentation on it. Is it available? Or examples? I enabled it with defaults, and it alerted on a bunch of hosts, but that didn't make sense to me, given the contents of the default lookup file.

baldwintm
Path Finder

Documentation has been updated on splunkbase:
https://splunkbase.splunk.com/app/3247/#/details

Also, the version 3.2.0 has been released, and has an updated README.md.
It also makes the app install process easier, especially for search head clusters.

Please take a look at this updated documentation, and let me know if there are still questions about this app.

tlmayes
Contributor

Thanks for the update. Works as expected. Documentation appreciated. Great work

0 Karma

baldwintm
Path Finder

Sorry for the delayed response:

  • There is a README.md file that is in the app. This is has more information.
  • There is a new version that is almost ready to be released, the documentation will be updated when that happens
  • There isn't any data that is specific to this app (it uses whatever data you have in splunk), so there isn't any traditional "example" data that we can include

Let me know if this helps, or if you have any additional questions that I can help with.

baldwintm
Path Finder

@tlmayes - The current version is not "visible" since there are not really any dashboards in the app. (The next version will be "visible", and will have a dashboard).

The goal of this app is to alert you when data stops coming into splunk. The app setup screen doesn't seem to work properly in clustering, so you will probably need to update the macros manually (this issue will be fixed in the next release).
The "default_contact" macro is the primary macro that you'll want to update. Change this to the email address that you want to send the alerts to.
Be aware that you might get a rather large email every hour until you update the "expectedTime" lookup table.

Let me know if there are any additional questions about this as you continue to work though the tuning process.
I hope to provide better documentation in the next release also.

0 Karma

sloshburch
Splunk Employee
Splunk Employee

The app page references a setup page. Was that not in there and no README in it?

Other than that, I guess we defer to the app author at Hurricane?

0 Karma

tlmayes
Contributor

I was asked to install this app in our enterprise environment. Did so, as well as installed in lab for testing/validation. App does not show up in "visible" apps in either environment, even though is set to "visible". Followed the README for both (since one is clustered and uses App distribution).

So, stupid question. What is it supposed to do? I get a search bar, and access to lookups (specifically expectedTime.csv (with no data))

0 Karma

a212830
Champion

I'll check for a README. That said, an app shouldn't be considered certified without proper doc and examples...

0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...