Monitoring Splunk

Is there a way to add a custom Server Role in Monitoring Console?

att35
Builder

Hi,

Does anyone know a way to add a custom Server role in monitoring console? We have a staging instance which we use only for deploying/configuring apps before they are moved to Deployer. Existing roles do not have anything that matches Staging so we end up selecting Search Head role for this server.

Just wondering if this can be done so that Console can be more consistent with current setup.

alt text

Thanks,

~ Abhi

0 Karma
1 Solution

ragedsparrow
Contributor

These are Splunk server roles for the Monitoring Console dashboard, so even if your server was a Staging server, it would still be a Search Head, Indexer, etc. These roles are defined so that the Monitoring Console knows that they need to be included in the proper dashboards. What you can do, in a distributed monitoring environment is set Custom Groups, where you could group it as a Staging Server, Prod SHC, Prod IDX Cluster, etc.

View solution in original post

0 Karma

ragedsparrow
Contributor

These are Splunk server roles for the Monitoring Console dashboard, so even if your server was a Staging server, it would still be a Search Head, Indexer, etc. These roles are defined so that the Monitoring Console knows that they need to be included in the proper dashboards. What you can do, in a distributed monitoring environment is set Custom Groups, where you could group it as a Staging Server, Prod SHC, Prod IDX Cluster, etc.

0 Karma

att35
Builder

Thank you.

We have defined the custom groups to identify these servers but it would have been nice to create new roles so that it doesn't club such servers as a Search Head under Overview.

~ Abhi.

0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, August edition

In the dynamic world of cybersecurity, staying ahead means constantly solving new puzzles and optimizing your ...

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Whether you're managing complex deployments or looking to future-proof your data infrastructure, this session ...