Security

Monitoring Console: How to edit roles via CLI or configuration files?

Aftend1971
Explorer

How to edit standalone roles in monitoring console? There (https://answers.splunk.com/answers/318342/how-to-change-server-roles-in-the-distributed-mana.html) is information about $SPLUNK_HOME/etc/apps/splunk_management_console/lookups/assets.csv but I guess that these roles are generated elsewhere (probably by DMC itself apps/splunk_monitoring_console/bin/dmc_config.py ?? ) ... So editing this file is not a right way, right?

There is also mention about distsearch.conf, but I did not find any info about roles. Probably splunk_monitoring_console_assets.conf has to have peers from distsearch.conf, but roles should be configured elsewhere.

Any idea? Except manual edit in GUI. Thanks

EDIT:
Monitoring Console should be refreshed after change anyway. But I did not find any CLI command, or REST requests to refresh it.

EDIT2:
Seems that output is populated from Search: DMC Asset - Build Standalone Asset Table

0 Karma

splunker12er
Motivator

There is no Splunk CLI command to edit splunk server roles.

The server role are set inside a csv file $SPLUNK_HOME/etc/apps/splunk_management_console/lookups/assets.csv you can edit this file using some editor and if you if you may wish have a backup - though its populated by script by default it doesn't somehow doesnt manage to set proper roles to you env,. you may need to change it manually

0 Karma

Aftend1971
Explorer

But $SPLUNK_HOME/etc/apps/splunk_management_console/lookups/assets.csv is populated from upstream script.

Even if you edit $SPLUNK_HOME/etc/apps/splunk_management_console/lookups/assets.csv roles are not refreshed in monitoring console.

I guess this file can be overrided every time that script is triggered.

DMC Asset - Build Standalone Asset Table leads to [dmc_get_local_instance_asset_computed_groups] macro, which will populate assets.csv
from
https://127.0.0.1:8089/services/server/info?output_mode=json

http://docs.splunk.com/Documentation/Splunk/7.0.2/RESTREF/RESTsystem#server.2Froles

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...