Deployment Architecture

How can I automate the data on-boarding process?

dharveynswccd
Path Finder

I have Splunk Universal Forwarder installed on RHEL. I have hundreds of stanzas manually written in $SPLUNKHOME/etc/apps//default/ to facilitate log data on-boarding from sources on the network (our Splunk PS configured it this way initially). Can this process be automated so that when new systems are introduced on the network they can be detected, and a new stanza be written/current stanza be updated manually?

Tags (1)
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...