Getting Data In

btool cheat sheet

youngsuh
Contributor

Does anyone have a cheat sheet for btool to help newbies?

Here is my version of btool cheat sheet:

 

splunk btool <conf_file_prefix> <sub-cmd> <context> --debug "%search string%"
splunk show config <config file name> | grep -v "system\/default"

Step 1.
splunk btool inputs list --debug "%search string%"  >> /tmp/splunk_inputs.txt
Step 2.
Import into excel using space as a separator.
Step 3.  Use excel to filter feature to look for the settings

 

Explanation: 

<conf_file_prefix>: props, inputs, outputs, transforms

<sub-cmd>:  list, display, user, dir

<context>: --app=search

"%serch string%": input the search you're looking for

I'd prefer piping the command to "less" command.

Splunk documents:  https://docs.splunk.com/Documentation/Splunk/8.0.5/Troubleshooting/CommandlinetoolsforusewithSupport...

https://docs.splunk.com/Documentation/Splunk/8.0.5/Troubleshooting/Usebtooltotroubleshootconfigurati...

https://docs.splunk.com/Documentation/Splunk/8.0.5/Troubleshooting/CommandlinetoolsforusewithSupport

External Site:

https://splunkonbigdata.com/2018/10/03/splunk-btool/

Thanks, everyone who replied.  I'd consolidated the information into the top page.

Labels (1)
Tags (1)
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @youngsuh,

I didn't find a page as you would and it's a strange thing because Splunk documentation is usually very complete and structured.

Anyway, in these pages, you can find all the infos you need:

https://docs.splunk.com/Documentation/Splunk/8.0.5/Troubleshooting/Usebtooltotroubleshootconfigurati...

https://docs.splunk.com/Documentation/Splunk/8.0.5/Troubleshooting/CommandlinetoolsforusewithSupport

https://splunkonbigdata.com/2018/10/03/splunk-btool/

Ciao.

Giuseppe

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Try 

splunk btool help

 I prefer to pipe btool output to 

grep -v "system\/default"

to eliminate noise from the default settings. 

---
If this reply helps you, Karma would be appreciated.

isoutamo
SplunkTrust
SplunkTrust

And remember that what you got from btool is what is on disk. If/when you want to see what is running config you must use 

splunk show config <config file name>

r. Ismo 

gcusello
SplunkTrust
SplunkTrust

Hi @youngsuh,

I didn't find a page as you would and it's a strange thing because Splunk documentation is usually very complete and structured.

Anyway, in these pages, you can find all the infos you need:

https://docs.splunk.com/Documentation/Splunk/8.0.5/Troubleshooting/Usebtooltotroubleshootconfigurati...

https://docs.splunk.com/Documentation/Splunk/8.0.5/Troubleshooting/CommandlinetoolsforusewithSupport

https://splunkonbigdata.com/2018/10/03/splunk-btool/

Ciao.

Giuseppe

yulsplunkops
Engager

I use the good old grep command when I needed a list of indexes referenced in all inputs on all folders ; like this:  

splunk btool inputs list --debug | grep index



 

0 Karma

mwk1000
Path Finder

that is my 99% use case for btool , the aggregated list of xxxxx.conf by file --debug then filter with grep.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

If you know stanza name you should add also it. 
Currently there is also splunk app called Admin's little helper, which you could use to run btool from MC or splunk cloud. I strongly recommended to install and use it in any distributed environments!


https://splunkbase.splunk.com/app/6368

0 Karma

Abhay
Explorer

https://splunkonbigdata.com/splunk-btool/

 

This is the new link for btool in Splunkonbigdata.com 

gcusello
SplunkTrust
SplunkTrust

Hi @youngsuh,

happy splunking!

Ciao.

Giuseppe

P.S.: Karma Points are appreciated by me and the other contributors 😉

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...