Splunk Enterprise Security

Centralized Splunk config synchronization like rsync over HTTPS

responsys_cm
Builder

I have a customer with a very unique network environment. They will have multiple ES clusters worldwide. The only way those clusters can talk to a central region is via web proxies that don't support SOCK5 and can't anytime soon for a variety of political reasons.

Does anyone know of a method or tool to achieve something like rsync over HTTPS so that I can have a centralized Splunk instance that I use to configure ES, TAs, dashboards, etc. and the distributed ES clusters can pull down the content and keep it in sync?

Thanks.

C

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

A globally accessible Deployment Server that all the ES instances can pull their configurations from...

0 Karma

gjanders
SplunkTrust
SplunkTrust
0 Karma

responsys_cm
Builder

garethatiag... thanks. Appetite looks pretty cool. It wouldn't work for my customer environment though. The ES clusters that need to have their apps synchronized can only pull from the central location.

0 Karma

tmarlette
Motivator

I've used GitHub to sync config globally before, but I don't know if you have that option here.

0 Karma

responsys_cm
Builder

tmarlette... that's a great idea. They'd have to run their own internal git server on that central Splunk instance, but that should allow git requests to flow between the proxies.

Thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...