Security

Monitoring Console: How to edit roles via CLI or configuration files?

Aftend1971
Explorer

How to edit standalone roles in monitoring console? There (https://answers.splunk.com/answers/318342/how-to-change-server-roles-in-the-distributed-mana.html) is information about $SPLUNK_HOME/etc/apps/splunk_management_console/lookups/assets.csv but I guess that these roles are generated elsewhere (probably by DMC itself apps/splunk_monitoring_console/bin/dmc_config.py ?? ) ... So editing this file is not a right way, right?

There is also mention about distsearch.conf, but I did not find any info about roles. Probably splunk_monitoring_console_assets.conf has to have peers from distsearch.conf, but roles should be configured elsewhere.

Any idea? Except manual edit in GUI. Thanks

EDIT:
Monitoring Console should be refreshed after change anyway. But I did not find any CLI command, or REST requests to refresh it.

EDIT2:
Seems that output is populated from Search: DMC Asset - Build Standalone Asset Table

0 Karma

splunker12er
Motivator

There is no Splunk CLI command to edit splunk server roles.

The server role are set inside a csv file $SPLUNK_HOME/etc/apps/splunk_management_console/lookups/assets.csv you can edit this file using some editor and if you if you may wish have a backup - though its populated by script by default it doesn't somehow doesnt manage to set proper roles to you env,. you may need to change it manually

0 Karma

Aftend1971
Explorer

But $SPLUNK_HOME/etc/apps/splunk_management_console/lookups/assets.csv is populated from upstream script.

Even if you edit $SPLUNK_HOME/etc/apps/splunk_management_console/lookups/assets.csv roles are not refreshed in monitoring console.

I guess this file can be overrided every time that script is triggered.

DMC Asset - Build Standalone Asset Table leads to [dmc_get_local_instance_asset_computed_groups] macro, which will populate assets.csv
from
https://127.0.0.1:8089/services/server/info?output_mode=json

http://docs.splunk.com/Documentation/Splunk/7.0.2/RESTREF/RESTsystem#server.2Froles

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...