Deployment Architecture

Programatically adding and removing mounts for indexing

msacks
Explorer

I would like to know how I might go about automatically adding and removing log mounts for this environment, and making sure the corresponding data sources that I am changing to be indexed also update a specific custom application that encompasses that mount as well.

Tags (2)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi msacks

yes, you can do this with the REST API, read more here: RESTconfigurations

cheers

0 Karma

msacks
Explorer

I second gkanapathy comment. It's really unclear what you are trying >to do, and more importantly, what you are trying to do with splunk.

Programmatically update my Splunk configurations using an API.

0 Karma

Lowell
Super Champion

No response. I'm giving a down vote.

0 Karma

Lowell
Super Champion

I second gkanapathy comment. It's really unclear what you are trying to do, and more importantly, what you are trying to do with splunk. You can click the "edit" button under your question and add some additional detail.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

I'm confused about what you're looking for. Splunk doesn't really take care of mounting or unmounting filesystems, and I'm not sure what you mean by "update a specific application". You mean if you change out a filesystem and path, you have to update the inputs.conf?

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...