Security

Monitoring Console: How to edit roles via CLI or configuration files?

Aftend1971
Explorer

How to edit standalone roles in monitoring console? There (https://answers.splunk.com/answers/318342/how-to-change-server-roles-in-the-distributed-mana.html) is information about $SPLUNK_HOME/etc/apps/splunk_management_console/lookups/assets.csv but I guess that these roles are generated elsewhere (probably by DMC itself apps/splunk_monitoring_console/bin/dmc_config.py ?? ) ... So editing this file is not a right way, right?

There is also mention about distsearch.conf, but I did not find any info about roles. Probably splunk_monitoring_console_assets.conf has to have peers from distsearch.conf, but roles should be configured elsewhere.

Any idea? Except manual edit in GUI. Thanks

EDIT:
Monitoring Console should be refreshed after change anyway. But I did not find any CLI command, or REST requests to refresh it.

EDIT2:
Seems that output is populated from Search: DMC Asset - Build Standalone Asset Table

0 Karma

splunker12er
Motivator

There is no Splunk CLI command to edit splunk server roles.

The server role are set inside a csv file $SPLUNK_HOME/etc/apps/splunk_management_console/lookups/assets.csv you can edit this file using some editor and if you if you may wish have a backup - though its populated by script by default it doesn't somehow doesnt manage to set proper roles to you env,. you may need to change it manually

0 Karma

Aftend1971
Explorer

But $SPLUNK_HOME/etc/apps/splunk_management_console/lookups/assets.csv is populated from upstream script.

Even if you edit $SPLUNK_HOME/etc/apps/splunk_management_console/lookups/assets.csv roles are not refreshed in monitoring console.

I guess this file can be overrided every time that script is triggered.

DMC Asset - Build Standalone Asset Table leads to [dmc_get_local_instance_asset_computed_groups] macro, which will populate assets.csv
from
https://127.0.0.1:8089/services/server/info?output_mode=json

http://docs.splunk.com/Documentation/Splunk/7.0.2/RESTREF/RESTsystem#server.2Froles

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...