Monitoring Splunk

How to change server roles in the Distributed Management Console using the CLI or conf files?

kimche
Path Finder

In the console, you can change the server roles of the instances in the Distributed Management Console manually. How can you do this using CLI commands or editing conf files? There is little to no documentation about configuring DMC using CLI.

Thanks!

1 Solution

MuS
Legend

Hi kimche,

There is no special Splunk CLI command to do this.
But, since the server role of an instance is set in $SPLUNK_HOME/etc/apps/splunk_management_console/lookups/assets.csv you can basically use any method to modify this file; vi for example, Puppet, Deployment server or the Splunk lookup editor just to name a few.

Hope this helps ...

cheers, MuS

View solution in original post

MuS
Legend

Hi kimche,

There is no special Splunk CLI command to do this.
But, since the server role of an instance is set in $SPLUNK_HOME/etc/apps/splunk_management_console/lookups/assets.csv you can basically use any method to modify this file; vi for example, Puppet, Deployment server or the Splunk lookup editor just to name a few.

Hope this helps ...

cheers, MuS

ykou_splunk
Splunk Employee
Splunk Employee

The server role is not only related to the assets.csv file, but also related to distributed search groups, which is a different story. The assets.csv file needs to be in sync with the distributed search group. But there is no easy way to modify distributed search group. So, I would suggest just go to the Setup UI page and manually modify server role there (instead of directly editing assets.csv), to avoid any unexpected behavior.

MuS
Legend

Okay, if it's related to the distributed search group as well one can modify the distsearch.conf file to create or modify the group http://docs.splunk.com/Documentation/Splunk/6.3.0/DistSearch/Distributedsearchgroups . This can be done using git, puppet, vi, rsync ......... what ever your flavour is.

kimche
Path Finder

Thanks ykou and MuS: I managed to do it by making distributed search groups. Still weird that the assets.csv is missing though.

0 Karma

kimche
Path Finder

Thank for your answer MuS! In my machine there is no assets.csv (or lookups folder) at all. Does this folder and csv file automatically get created when the DMC machine gets launched or do I need to do another step to enable it (I did already add the search peers in the distributed search).

0 Karma

MuS
Legend

This will probably be created during the initial setup of DMC http://docs.splunk.com/Documentation/Splunk/6.3.0/DMC/Deploymentsetupsteps

0 Karma
Get Updates on the Splunk Community!

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...

Alerting Best Practices: How to Create Good Detectors

At their best, detectors and the alerts they trigger notify teams when applications aren’t performing as ...

Discover Powerful New Features in Splunk Cloud Platform: Enhanced Analytics, ...

Hey Splunky people! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2408. In this ...