Splunk Enterprise

How do I check to see if my Splunk Technology add-ons (TAs) are working properly on Splunk Ent or ES? Thanks a mil.

SamHTexas
Builder

Since TAs run in the background & usually not viewed, how do I check on their health? Any useful SPLs are appreciated.

Labels (2)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

What do you mean by "TA-s run in background"?

TA-s on its own don't "run". They might provide some scripted/modular inputs and then you might simply monitor the destination indexes, but often they just contain props/transforms/lookups.

0 Karma

SamHTexas
Builder

Thank u for your response. Am familiar with TAs function. What I mean is they are not visible like apps that do a certain function. So we download TA like we do with Apps. What am looking for is a SPL to tell me if a TA is broken or did not install properly & not doing it's duty. Please advise.

Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

How would you like to decide (especially without knowing details of particular TA) whether it's doing its job or not?

For example - you install a TA for windows but misconfigure the inputs on your UF-s and they send the data with wrong sourcetype so no props/transforms from said TA are applied in searchtime because they don't catch the events. How would you like to detect that?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...