Hi all,
Rookie Splunk question here 🙂
In my previous life I worked mostly with Tivoli, so this Splunk world is still pretty new to me and I’m trying to understand the best practices.
I have installed the Splunk Add‑on for Microsoft SCOM and I’m receiving SCOM data into a dedicated SCOM index. I can also see the events on the ITSI side, so the integration itself seems to be working fine.
I have a couple of questions:
I currently have two Windows Heavy Forwarders, both configured with HEC and the SCOM Add‑On.
Now all SCOM events appear to be duplicated, as they are coming in through both HEC endpoints.
I have done some event enrichment in the SCOM Integration Search in ITSI (for example: assigning responsible team, routing info, etc.).
However, it looks like not all events are enriched, and I can’t really figure out why:
Is this the correct place to do the enrichment, or am I missing something about how the SCOM Integration Search works?
Any guidance or pointers would be greatly appreciated.
Thanks in advance!
Hi @Kaitsu
The duplication of events here is expected if running the SCOM inputs on multiple HF - If you need HA then I would suggest having the secondary prepared but with the modular input turned off.
Regarding your search issue - are all the events the same sourcetype? Are you able to identify any distinction between the different hosts which do and do not get the enrichment?
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing
Hi @Kaitsu
The duplication of events here is expected if running the SCOM inputs on multiple HF - If you need HA then I would suggest having the secondary prepared but with the modular input turned off.
Regarding your search issue - are all the events the same sourcetype? Are you able to identify any distinction between the different hosts which do and do not get the enrichment?
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing