All Apps and Add-ons

webping on 4.2.2

_z_
Explorer

Does webping app work on 4.2.2?

The app instructions state:

To start: Copy bundle into your
etc/bundles directory Modify the
following arguements in urls.conf

I am guessing this means copy from ../splunk/etc/apps/webping/default/bundles.conf

But I do not see a '../splunk/etc/bundles'... or does this mean just to copy the above into 'etc'?

0 Karma
1 Solution

_z_
Explorer

Found README in app bundle. Clearer instructions there, works with 4.2.2.

> ABOUT WEBPING BUNDLE
> ==================== This bundle will check a set of webpages every interval
> and index the result, time, size and
> optionally content and or crc of
> page(s).
> 
> To start: Copy bundle into your
> $SPLUNK_HOME/etc/apps directory Modify
> the following arguements in urls.conf 
> For each url you wish to check, add a
> stanza like the following
>      [mypage]
>      url = http://www.mypage.com
>      timeout = 10
>      indexResults = false
>      userAgent = Mozilla/4.0
>      indexMD5 = false
>      indexResults = false
> 
> NOTE: A true value can be indicated by
> any of the following:
> 
>    true     1     t     on     yes
> 
> You can add as many pages above as you
> wish. Make sure that each page has a
> unique [name] ex. [mypage] If you
> index the Results, be careful the
> payload can be large.
>      
>     If you have bugs or suggestions please let us know.
> [email protected]. Good luck!
> 
> TODO:
> ============
>  - add in the filtering and matching from the imap bundle so you can filter
> content
>  - add back in the n level crawling
>  - add support for auth/login

View solution in original post

_z_
Explorer

Found README in app bundle. Clearer instructions there, works with 4.2.2.

> ABOUT WEBPING BUNDLE
> ==================== This bundle will check a set of webpages every interval
> and index the result, time, size and
> optionally content and or crc of
> page(s).
> 
> To start: Copy bundle into your
> $SPLUNK_HOME/etc/apps directory Modify
> the following arguements in urls.conf 
> For each url you wish to check, add a
> stanza like the following
>      [mypage]
>      url = http://www.mypage.com
>      timeout = 10
>      indexResults = false
>      userAgent = Mozilla/4.0
>      indexMD5 = false
>      indexResults = false
> 
> NOTE: A true value can be indicated by
> any of the following:
> 
>    true     1     t     on     yes
> 
> You can add as many pages above as you
> wish. Make sure that each page has a
> unique [name] ex. [mypage] If you
> index the Results, be careful the
> payload can be large.
>      
>     If you have bugs or suggestions please let us know.
> [email protected]. Good luck!
> 
> TODO:
> ============
>  - add in the filtering and matching from the imap bundle so you can filter
> content
>  - add back in the n level crawling
>  - add support for auth/login
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...