Monitoring Splunk

Configuring distributed monitoring console without the UI

Isaac_Hailperin
Explorer

I am trying to configure the distributed monitoring console without the UI (for automation purposes). It seems that I have gotten most things right - all instances show up the way I want them to, however they are all marked as "unreachable".

It seems that I must do the step where I provide credentials for the mc host to login to the monitored host. However I cannot figure out what this step actually does.

Also I cannot find anything that hints to the credentials being stored anywhere. So what does this login process actually do, and how can I mimic that bevhaviour for the mc from the commandline/ via config files?

Any insight on how the setup process works behind the scene would be appreciated.

Labels (1)
0 Karma

tej57
Contributor

Hello @Isaac_Hailperin ,

Can you share what steps have you taken so far? That would help understand what is actually missing.


Thanks,
Tejas.

0 Karma
Get Updates on the Splunk Community!

Holistic Visibility and Effective Alerting Across IT and OT Assets

Instead of effective and unified solutions, they’re left with tool fatigue, disjointed alerts and siloed ...

SOC Modernization: How Automation and Splunk SOAR are Shaping the Next-Gen Security ...

Security automation is no longer a luxury but a necessity. Join us to learn how Splunk ES and SOAR empower ...

Ask It, Fix It: Faster Investigations with AI Assistant in Observability Cloud

  Join us in this Tech Talk and learn about the recently launched AI Assistant in Observability Cloud. With ...