Monitoring Splunk

Would like to build basic dashboards showing graphs based on the contents of monitored logs on macOS

Herman
Explorer

However, so far, I can't derive anything meaningful for building the dashboards.

I would like to set Splunk to monitor the host operating systems logs files and/or performance data on macOS. I get data in from sources including '/var/log' and '/Library/Logs' but don't see anything meaningful from the data with certain field values filtered. I would also like to monitor the performance data but not sure where they locate at or how to filter the values. Any help would be appreciated! Thanks!

  • System Log Folder: /var/log
  • System Log: /var/log/system.log
  • Mac Analytics Data: /var/log/DiagnosticMessages
  • System Application Logs: /Library/Logs
  • System Reports: /Library/Logs/DiagnosticReports
  • User Application Logs: ~/Library/Logs (in other words, /Users/NAME/Library/Logs)
  • User Reports: ~/Library/Logs/DiagnosticReports (in other words, /Users/NAME/Library/Logs/DiagnosticReports)
Labels (1)
0 Karma

Herman
Explorer

Is the below page what I am supposed to follow? However, I can't find the OSX after clicking 'Add Data'

https://docs.splunk.com/Documentation/InfraApp/2.2.3/Admin/AddDataMacOSX

For performance data, I assume I should monitor the cpu, ram, battery usage, etc. for creating meaningful dashboards? However, are there any logs for this performance data on macOS? If not, how should I get this data in from maybe Activity Monitor? Thanks!

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...