All Apps and Add-ons

Where does the Splunk Add-on for Box store checkpoint information?

scsvnovonordisk
New Member

I recently install the add-on and it appears to be working fine. However, I'd like to understand more around how the app works. Can someone explain how the add-on stores checkpoint information and where it puts it on the file system?

I found the created_after variable in the box_default section of box.conf, but it doesn't appear to have been changed since I installed the add-on. The python is a bit complicated but I see reference to a checkpoint_dir setting (which I don't see set anywhere, nor can I tell what it defaults to) as well as it functions that look like they use the rest_api to save the checkpoint somewhere. But i don't see what rest endpoint it uses.

Can somebody help me figure it out?
Thanks!

Tags (1)
0 Karma
1 Solution

rpille_splunk
Splunk Employee
Splunk Employee

Have you checked the documentation? http://docs.splunk.com/Documentation/AddOns/released/Box/Troubleshooting#Reset_checkpoint_for_histor... suggests that there is an events checkpoint file under $SPLUNK_HOME/var/lib/splunk/modinputs/box_service.

View solution in original post

rpille_splunk
Splunk Employee
Splunk Employee

Have you checked the documentation? http://docs.splunk.com/Documentation/AddOns/released/Box/Troubleshooting#Reset_checkpoint_for_histor... suggests that there is an events checkpoint file under $SPLUNK_HOME/var/lib/splunk/modinputs/box_service.

scsvnovonordisk
New Member

Totally missed that page. Thanks!

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...