Getting Data In

Is it possible to run 'splunk list monitor' for a universal forwarder (deployment client) remotely?

mfrost8
Builder

Hi. I've got some rather complex rules (at least to me) that I'm pushing out to a remote Windows universal forwarder that is a deployment client. I'd like to confirm that the files it's trying to watch line up with what the rules I wrote are (I think) telling it to do. Normally, I'd go onto the universal forwarder and run 'splunk list monitor' to see what the forwarder thinks it's monitoring. In this case, however, I don't have access to the universal forwarder host.

Of course I could, in theory, just look to see if events from the sources I want are coming in and that there are no events from sources I don't want. However, I don't actually know if all of these sources are generating events regularly. In other words, the absence of events from a particular source might not be unusual, but I'd still like to know if Splunk is watching that file anyway.

Is there any way to run 'splunk list monitor' or its equivalent through Splunk? Maybe some debugging flag I could turn on that would dump that to splunkd.log so I could see that via _internal from the universal forwarder?

While I can't get on the client to even see if events are going into specific logs that might not be having new events going into them, I could at least feel more confident if I knew that Splunk thought it was watching that file.

This is Splunk 6.2.1, by the way.

Thanks

0 Karma
1 Solution

MuS
Legend

Hi mfrost8,

take a look at the docs http://docs.splunk.com/Documentation/Splunk/6.2.1/Admin/AccessandusetheCLIonaremoteserver#CLI_comman... where you find a list of commands which are not usable from remote. Based on that list it should be possible to use it, if you did enable remote access before http://docs.splunk.com/Documentation/Splunk/6.2.1/Admin/AccessandusetheCLIonaremoteserver#Enable_rem...

Hope this helps ...

cheers, MuS

View solution in original post

MuS
Legend

Hi mfrost8,

take a look at the docs http://docs.splunk.com/Documentation/Splunk/6.2.1/Admin/AccessandusetheCLIonaremoteserver#CLI_comman... where you find a list of commands which are not usable from remote. Based on that list it should be possible to use it, if you did enable remote access before http://docs.splunk.com/Documentation/Splunk/6.2.1/Admin/AccessandusetheCLIonaremoteserver#Enable_rem...

Hope this helps ...

cheers, MuS

mfrost8
Builder

Thanks very much. I think this was some functionality that slipped in during some release that I never knew about. This solved my problem.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...