Splunk Enterprise

How to recreate cpu memory usage searches?

TheBravoSierra
Path Finder

Because we are unable to use the monitoring console in Splunk Mobile, I would like to create our own monitoring console dashboard of sorts. Beginning with these searches, status, cpu usage, and memory usage of indexers and search heads. Does anyone have these searches available or know where I can locate them?

See attached screenshot for example.

Thanks

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Dashboards are in $SPLUNK_HOME/etc/apps/<app name>/default/data/ui/views.  Splunk tends to obfuscate their dashboard code so you'll likely have better luck viewing the panels by clicking on the "Open in Search" icon in the panel.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Why can you not use MC on mobile?

The searches you seek are all in $SPLUNK_HOME/etc/apps/splunk_monitoriing_console/default/savedsearches.conf.

---
If this reply helps you, Karma would be appreciated.

TheBravoSierra
Path Finder

I have access to view MC in Splunk Web but when I grant access for the same user to see it in mobile, they're unable to see it. Are you able to? Have you confirmed that is a supported functionality in Splunk Mobile? 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I'm unable to see the MC using Splunk Mobile, but that doesn't mean you can't copy the MC's searches into an app the mobile user can view.

---
If this reply helps you, Karma would be appreciated.
0 Karma

TheBravoSierra
Path Finder

In the location you specified above, I only see the saved searches. I don't see the searches for the dashboard panels. Would those be somewhere else?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Dashboards are in $SPLUNK_HOME/etc/apps/<app name>/default/data/ui/views.  Splunk tends to obfuscate their dashboard code so you'll likely have better luck viewing the panels by clicking on the "Open in Search" icon in the panel.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...