Getting Data In

Using different indexes in splunk app for jenkins

ivohechmann
Explorer

Hi all;

Regarding the Splunk App for Jenkins

We have multiple jenkins instances in our environment; Each project is in charge of its own jenkins. As there are ways to prevent sensible data to be logged by jenkins, the risk that something that shouldn't be viewed by everyone gets logged by jenkins is considered high. 

my first approach was to modify the splunk app, one instance of the app per jenkins/project, but until now the result is useless.. before I dig deeper: is there another way to "separate" the data or the view on the data in the app?

Thank you very much for any input...

ivo

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

The first thing to do if you want to limit access to data would be to separate the events into different indexes. Then you'll be able to assign different permissions for each of those indexes.

Depending on how the app is written (I haven't seen it) it might require additional configuration but just as well it might be all it requires.

0 Karma

ivohechmann
Explorer

Yes indeed. The app references 3 indexes which can be extended by macros:

jenkins_statistics_index
jenkins_console_index
jenkins_index

but as long as the index jenkins_statistics is directly referenced in 

  • appserver/static/pages/audit.js
  • appserver/static/pages/build.js
  • appserver/static/pages/health.js
  • appserver/static/pages/node.js

the app does not work as designed...

Creating a splunk support case for this, hope for support for unsupported app 🙂

Thank you for your hints, 

ivo

0 Karma

PickleRick
SplunkTrust
SplunkTrust

As you already noticed - this is not a Splunk supported app so there is a very very remote probability that anyone looks into it. This is mostly on a "as-is" basis so short of manually fiddling with the app yourself your choices are fairly limited.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...