Monitoring Splunk

How do I configure Splunk App Mets Woot to work in my environment?

SamHTexas
Contributor

How do I configure Splunk App Mets Woot to work in my environment? I installed it on my cluster master & re-started the server, I keep getting "no results found" .  It is the latest version I just downloaded from Splunk base.

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Per the app's installation instructions

2. Install the app on a search head or search head cluster.
---
If this reply helps you, an upvote would be appreciated.
0 Karma

gjanders
SplunkTrust
SplunkTrust

Also pasting the slack response in case it helps. Richgalloway's answer is correct, SHC or SH is where these apps go

There are a lot of options for finding hosts or sources that stop submitting events: 

Meta Woot! https://splunkbase.splunk.com/app/2949/ 

TrackMe https://splunkbase.splunk.com/app/4621/ 

Broken Hosts App for Splunk https://splunkbase.splunk.com/app/3247/ 

Alerts for Splunk Admins ("ForwarderLevel" alerts) https://splunkbase.splunk.com/app/3796/ 

Monitoring Console https://docs.splunk.com/Documentation/Splunk/latest/DMC/Configureforwardermonitoring 

Deployment Server https://docs.splunk.com/Documentation/DepMon/latest/DeployDepMon/Troubleshootyourdeployment#Forwarde...

 

Some helpful posts: 

https://lantern.splunk.com/hc/en-us/articles/360048503294-Hosts-logging-data-in-a-certain-timeframe 

https://www.duanewaddle.com/proving-a-negative/

0 Karma