Getting Data In

Is it possible to run 'splunk list monitor' for a universal forwarder (deployment client) remotely?

mfrost8
Builder

Hi. I've got some rather complex rules (at least to me) that I'm pushing out to a remote Windows universal forwarder that is a deployment client. I'd like to confirm that the files it's trying to watch line up with what the rules I wrote are (I think) telling it to do. Normally, I'd go onto the universal forwarder and run 'splunk list monitor' to see what the forwarder thinks it's monitoring. In this case, however, I don't have access to the universal forwarder host.

Of course I could, in theory, just look to see if events from the sources I want are coming in and that there are no events from sources I don't want. However, I don't actually know if all of these sources are generating events regularly. In other words, the absence of events from a particular source might not be unusual, but I'd still like to know if Splunk is watching that file anyway.

Is there any way to run 'splunk list monitor' or its equivalent through Splunk? Maybe some debugging flag I could turn on that would dump that to splunkd.log so I could see that via _internal from the universal forwarder?

While I can't get on the client to even see if events are going into specific logs that might not be having new events going into them, I could at least feel more confident if I knew that Splunk thought it was watching that file.

This is Splunk 6.2.1, by the way.

Thanks

0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi mfrost8,

take a look at the docs http://docs.splunk.com/Documentation/Splunk/6.2.1/Admin/AccessandusetheCLIonaremoteserver#CLI_comman... where you find a list of commands which are not usable from remote. Based on that list it should be possible to use it, if you did enable remote access before http://docs.splunk.com/Documentation/Splunk/6.2.1/Admin/AccessandusetheCLIonaremoteserver#Enable_rem...

Hope this helps ...

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi mfrost8,

take a look at the docs http://docs.splunk.com/Documentation/Splunk/6.2.1/Admin/AccessandusetheCLIonaremoteserver#CLI_comman... where you find a list of commands which are not usable from remote. Based on that list it should be possible to use it, if you did enable remote access before http://docs.splunk.com/Documentation/Splunk/6.2.1/Admin/AccessandusetheCLIonaremoteserver#Enable_rem...

Hope this helps ...

cheers, MuS

mfrost8
Builder

Thanks very much. I think this was some functionality that slipped in during some release that I never knew about. This solved my problem.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...