Monitoring Splunk

Can I invoke Monitoring console custom_group in REST API Query?

nags
Engager

I am trying to define various functions for each component level. However I am having multiple Splunk environments and I wanted to split Indexer group by different region. Say I have 2 Indexers in A region and 5 in B region and 1 in C region. Apart from splunk_server_group=dmc_group_indexers can I call custom group in my REST query to fetch particular indexers in that region? Or is that possible to call via custom macro? Please throw some light on this

Labels (2)
Tags (1)
0 Karma

dhruv
Explorer
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...