All Apps and Add-ons

Splunk to uCMDB Integration

mbasharat
Contributor

I have been doing some research and need to know if there is any Splunk certified secure app in splunkbase for integrating Splunk to uCMDB OR what is the correct and tested procedure of doing so that we can get data from uCMDB to Splunk e.g. CIs, CI's attributes etc.? I was going thru Splunkbase and found only one app named CMDB-to-ITSI. It is not just indexing the uCMDB logfiles via Splunk. Appreciate your assistance in-advance. Thanks.

Tags (1)
0 Karma
1 Solution

ansif
Motivator

For HP uCMDB 11 version REST API is supported,you can use REST API to get all interested data from uCMDB.

View solution in original post

lekanneer
Loves-to-Learn Lots

I'm the creator of the CMDB-to-ITSI app. I also have experience with the uCMDB.

If you're looking for an efficient and functional ServiceNow to Splunk integration (also CMDB) take a look at: https://www.thedutchdatadifference.nl/splunk-servicenow/

I created that solution and continuously adding new features. I potentially can do the uCMDB to my solution so that you can make use of content and context from Splunk.

Indeed I can imagine that Splunk is having nice and rich fresh data that can be integrated to a CMDB.

0 Karma

stefan_d
Path Finder

And also what about the other direction?

Is anyone pushing inventory data from Splunk into uCMDB?

Not sure if the use case would make sense from a license cost perspective, but if you're already using a Splunk agent on a server can one not collect inventory type data (say once a week) via Splunk and use uCMDB's REST API to populate the CI in uCMDB? I think this could save the admin effort and license for using uCMDB's universal discovery agent/probe to collect data and update the CI.

I guess it depends on the integration effort. Also, this won't work if more than simple inventory data collection is required..

thoughts?

0 Karma

ansif
Motivator

For HP uCMDB 11 version REST API is supported,you can use REST API to get all interested data from uCMDB.

maciep
Champion

we use dbconnect to pull data from our cmdb. As of now, we don't ingest the data, but just run queries against it in splunk. We create an account, cmdb team gives us permissions/views and sql team ensures we're hitting the dr/inactive node, so we can't affect production activity.

0 Karma

maurelio79
Communicator

Hi, in our company we asked to people that managed uCMDB to create a job that get data from uCMDB, write a csv file and then copy the file on a universal forwarder machine via beta48 job, then we configured that universal forwarder to import that csv.

Regards

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...