Security

Monitoring Console: How to edit roles via CLI or configuration files?

Aftend1971
Explorer

How to edit standalone roles in monitoring console? There (https://answers.splunk.com/answers/318342/how-to-change-server-roles-in-the-distributed-mana.html) is information about $SPLUNK_HOME/etc/apps/splunk_management_console/lookups/assets.csv but I guess that these roles are generated elsewhere (probably by DMC itself apps/splunk_monitoring_console/bin/dmc_config.py ?? ) ... So editing this file is not a right way, right?

There is also mention about distsearch.conf, but I did not find any info about roles. Probably splunk_monitoring_console_assets.conf has to have peers from distsearch.conf, but roles should be configured elsewhere.

Any idea? Except manual edit in GUI. Thanks

EDIT:
Monitoring Console should be refreshed after change anyway. But I did not find any CLI command, or REST requests to refresh it.

EDIT2:
Seems that output is populated from Search: DMC Asset - Build Standalone Asset Table

0 Karma

splunker12er
Motivator

There is no Splunk CLI command to edit splunk server roles.

The server role are set inside a csv file $SPLUNK_HOME/etc/apps/splunk_management_console/lookups/assets.csv you can edit this file using some editor and if you if you may wish have a backup - though its populated by script by default it doesn't somehow doesnt manage to set proper roles to you env,. you may need to change it manually

0 Karma

Aftend1971
Explorer

But $SPLUNK_HOME/etc/apps/splunk_management_console/lookups/assets.csv is populated from upstream script.

Even if you edit $SPLUNK_HOME/etc/apps/splunk_management_console/lookups/assets.csv roles are not refreshed in monitoring console.

I guess this file can be overrided every time that script is triggered.

DMC Asset - Build Standalone Asset Table leads to [dmc_get_local_instance_asset_computed_groups] macro, which will populate assets.csv
from
https://127.0.0.1:8089/services/server/info?output_mode=json

http://docs.splunk.com/Documentation/Splunk/7.0.2/RESTREF/RESTsystem#server.2Froles

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...