Splunk Enterprise

How to recreate cpu memory usage searches?

TheBravoSierra
Path Finder

Because we are unable to use the monitoring console in Splunk Mobile, I would like to create our own monitoring console dashboard of sorts. Beginning with these searches, status, cpu usage, and memory usage of indexers and search heads. Does anyone have these searches available or know where I can locate them?

See attached screenshot for example.

Thanks

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Dashboards are in $SPLUNK_HOME/etc/apps/<app name>/default/data/ui/views.  Splunk tends to obfuscate their dashboard code so you'll likely have better luck viewing the panels by clicking on the "Open in Search" icon in the panel.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Why can you not use MC on mobile?

The searches you seek are all in $SPLUNK_HOME/etc/apps/splunk_monitoriing_console/default/savedsearches.conf.

---
If this reply helps you, Karma would be appreciated.

TheBravoSierra
Path Finder

I have access to view MC in Splunk Web but when I grant access for the same user to see it in mobile, they're unable to see it. Are you able to? Have you confirmed that is a supported functionality in Splunk Mobile? 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I'm unable to see the MC using Splunk Mobile, but that doesn't mean you can't copy the MC's searches into an app the mobile user can view.

---
If this reply helps you, Karma would be appreciated.
0 Karma

TheBravoSierra
Path Finder

In the location you specified above, I only see the saved searches. I don't see the searches for the dashboard panels. Would those be somewhere else?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Dashboards are in $SPLUNK_HOME/etc/apps/<app name>/default/data/ui/views.  Splunk tends to obfuscate their dashboard code so you'll likely have better luck viewing the panels by clicking on the "Open in Search" icon in the panel.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...