Deployment Architecture

Programatically adding and removing mounts for indexing

msacks
Explorer

I would like to know how I might go about automatically adding and removing log mounts for this environment, and making sure the corresponding data sources that I am changing to be indexed also update a specific custom application that encompasses that mount as well.

Tags (2)
0 Karma

MuS
Legend

Hi msacks

yes, you can do this with the REST API, read more here: RESTconfigurations

cheers

0 Karma

msacks
Explorer

I second gkanapathy comment. It's really unclear what you are trying >to do, and more importantly, what you are trying to do with splunk.

Programmatically update my Splunk configurations using an API.

0 Karma

Lowell
Super Champion

No response. I'm giving a down vote.

0 Karma

Lowell
Super Champion

I second gkanapathy comment. It's really unclear what you are trying to do, and more importantly, what you are trying to do with splunk. You can click the "edit" button under your question and add some additional detail.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

I'm confused about what you're looking for. Splunk doesn't really take care of mounting or unmounting filesystems, and I'm not sure what you mean by "update a specific application". You mean if you change out a filesystem and path, you have to update the inputs.conf?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...