Dashboards & Visualizations

Splunk with Legato

Branden
Builder

Does anyone use Splunk to capture statistics from their Legato back-ups?

Legato's mminfo reporting tool doesn't give me the information I need, but the e-mail sent out to us upon the completion of a saveset does. So I've been using Splunk to capture the mail spool for that account. This has actually worked pretty well. Thanks to some punct options I can produce an easier-to-read search result.

There are two things I'd like to do:

  1. Graph the time it completed versus the time it completed in previous days.
  2. Alert us if a back-up fails or does not complete by a certain time (probably two different alerts there).

Legato has utilities that do this for us, but it would be very nice if we could get Splunk to do it. One stop shopping, right?

Here's what an output looks like:

Date: Thu, 26 Aug 2010 05:23:23 -0400
From: root
Message-Id: <4798379873434.o87649853462@host.xyz.com>
To: oper
Subject: host1.xyz.com's savegroup completion
Cc: root

NetWorker savegroup: (alert) ProdDailycompleted, Total 8 client(s), 1 Failed, 7 Succeeded. 

Please see group completion details for more information.

Failed: host1
Succeeded: host2, host3, host4, host5


Is what I'm asking for possible/practical? Or is this just not worth the effort?

Thanks!

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Sure, it seems very easy. Most of the work will simply be in defining appropriate field extractions to get the data from your emails, and these look to be fairly straightforward regular expressions. If you're already getting the emails in Splunk, that's a big help. Make sure the time and "Failed" fields are extracted.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...