Dashboards & Visualizations

Is there any Mobile Iron device(MDM) integration documentation.

N92
Path Finder

I found some add on for dashboard. But we are facing some issue in integration like they are giving single option. How can i add multiple indexer in it.alt text

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi N92,
it's one year that I don't see MobileIron, but I remember that in MobileIron Appliance there's an embedded Splunk Forwarder and it must only be enabled by MobileIron Administration Console: it needs only to know Indexers, ports and use of SSL or not.
It isn't possible to configure anything else, because all the correct inputs to send logs to the MobileIron App for Splunk are correctly configurated and not modifiable.

In addition Forwarder is present only in Core and not in Sentry.
To monitor it, you have to configure this server to send logs by syslog and create your own dashboards on Splunk.

App and the few documentation is downloadable from MobileIron Support Site: one year ago documentation was very poor, but I could be not updated!

I hope to be helpful for you.

Bye.
Giuseppe

View solution in original post

schandrasekar
Loves-to-Learn

Hi , 

Our existing splunk architecture UF->HF->IDx->SH

MY question here is, is that the only way to get data from MobileIron Core to splunk? How do i send the data to HF instead of IDX?

 

thanks,
Sangeetha

 

0 Karma

schandrasekar
Loves-to-Learn

Hi, I have same question. Our exsiting splunk architecture UF->HF->IDX->SH. My question here, is that the only way to get data from MobileIron Core to Splunk or is there a way to send the data to HF instead of IDX

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi N92,
it's one year that I don't see MobileIron, but I remember that in MobileIron Appliance there's an embedded Splunk Forwarder and it must only be enabled by MobileIron Administration Console: it needs only to know Indexers, ports and use of SSL or not.
It isn't possible to configure anything else, because all the correct inputs to send logs to the MobileIron App for Splunk are correctly configurated and not modifiable.

In addition Forwarder is present only in Core and not in Sentry.
To monitor it, you have to configure this server to send logs by syslog and create your own dashboards on Splunk.

App and the few documentation is downloadable from MobileIron Support Site: one year ago documentation was very poor, but I could be not updated!

I hope to be helpful for you.

Bye.
Giuseppe

N92
Path Finder

Is there need to configure both(splunk forwarder & syslog).
What is the meaning to selecting SSL option? Means If we have enabled ssl on DS & indexers then it must be selected?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi N92,
you can configure your forwarders to send logs using SSL or not, it depends by your requisites and by the configuration you have on your Indexers.

Only one additional detail:
You can use Forwarder on MobileIron Core and you don't need to use syslogs on it.
Instead you need to use syslogs on Sentry because there isn't an embedded Forwarder.

Bye.
Giuseppe

0 Karma

N92
Path Finder

Thanks cusello.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...