Deployment Architecture

How do you configure weblogic with Splunk?

manekar
New Member

Hi,
Can you please let me know how to integrate weblogic with splunk 7.2

Thanks,
Swathi

Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

There's an app for that: https://splunkbase.splunk.com/app/1340/. It's a little outdated, but should get you started.

---
If this reply helps you, Karma would be appreciated.
0 Karma

manekar
New Member

Installed splunk 7.2 Forwarder in the linux server, Same server we have installed weblogic server (12c) and created domain as well.Here we are trying to achieve this weblogic applications to integrate with splunk app.

Splunk Home: /oracle/Splunk/splunk
Weblogic Home: /oracle/app/Middleware/wlserver

1) Deployed add-on file "oracle-weblogic-app-for-splunk_10-beta2.tgz" in the splunk application.
2) Deployed Sideview utils file "sideview_utils.tar" in the splunk application.
3) Updated the required weblogic & admin server details in inputs.conf and setWlstEnv.sh, as per the TA installation document. Later we placed the files in the below stated location

$SPLUNK_HOME/etc/deployment-apps/Function1_WebLogicServer_TA/local/inputs.conf &
$SPLUNK_HOME/etc/deployment-apps/Function1_WebLogicServer_TA/bin/setWlstEnv.sh folders.

E.g.: Below lines are modified in the inputs.conf file in our environment, did same for EVERY HOUR & # EVERY DAY

EVERY MINUTE
[script://./bin/runWlstScriptsMinute.sh /oracle/Splunk/splunk/etc/deployment-apps/Function1_WebLogicServer_TA /oracle/app/Middleware/wlserver_10.3]
disabled = false
index = wls
sourcetype = wls_trash
interval = 300

E.g.: Below lines are modified in the setWlstEnv.sh in our environment

export BEA_HOME=/oracle/app/Middleware
export SPLUNK_HOME=/oracle/Splunk/splunk
export DOMAIN_COUNT=1
export DOMAIN_PATH_1=/oracle/app/Middleware/user_projects/domains/soa_domain
export ADMIN_SERVER_1=AdminServer
export ADMIN_PORT_1=8080

Both files are updated as per the TA document "Splunk for Oracle Weblogic Server (v.1.0.1Beta)".
Then moving forward to step 6, documents says that "Once you have completed these configurations, deploy the TA to the forwarder residing on the WLS Admin Server by either Using the Splunk deployment server or copying the TA to the forwarder manually."

Please advise me regarding this deployment, am not clear in this step. Currently I have kept this config file folder "Function1_WebLogicServer_TA" under "$SPLUNK_HOME/etc/apps". We need to deploy on Indexer server Please let me know where & how to deploy this files.

Still am not receiving the data .
Thanks

0 Karma

rsodhia
Engager

I have followed the same steps and I am also not receiving the logs from weblogic. can someone comment who recently used the weblogic-add on.

0 Karma

manekar
New Member

I configured weblogic app am not able to see the JMX metrics or domain information
JVM,CPU in oracle weblogic app in splunk

0 Karma

manekar
New Member

I downloaded weblogic app.
i need to Know how to configure my weblogic application with splunk.Please provide me steps.

Thanks,
Swathi

0 Karma

manekar
New Member

I downloaded weblogic app.
i need to Know how to configure my weblogic application with splunk.Please provide me steps.

Thanks,
Swathi

0 Karma

richgalloway
SplunkTrust
SplunkTrust

These are the normal steps for a single-instance Splunk installation. Different procedures apply to distributed and clustered installations. These should be familiar to you from your Splunk admin classes.
1. Download the app to your workstation and uncompress it. Save the compressed file.
2. Review the README file and any other documentation for installation instructions.
3. Review the indexes.conf file for any indexes you need to add to your indexers. Add them to your local index configuration and disable them in the app.
4. Review the remaining .conf files to ensure the settings are suitable for your Splunk environment.
5. Sign in to Splunk as an admin and go to the Apps management page.
6. Click on the "Install app from file" button and select the downloaded (compressed) app file. Click Upload.
7. Wait for the installation to complete and allow Splunk to restart, if necessary.

Like I said, those are the normal steps. You will not be following them because the app is not intended for your version of Splunk and may work or may fail in unknown ways. You should follow steps 1-4 with the goal of understanding how the app works and how you can use that knowledge to create your own app. Keep in mind the app may not work at all with your version of weblogic.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...