Splunk Enterprise

How to recreate cpu memory usage searches?

TheBravoSierra
Path Finder

Because we are unable to use the monitoring console in Splunk Mobile, I would like to create our own monitoring console dashboard of sorts. Beginning with these searches, status, cpu usage, and memory usage of indexers and search heads. Does anyone have these searches available or know where I can locate them?

See attached screenshot for example.

Thanks

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Dashboards are in $SPLUNK_HOME/etc/apps/<app name>/default/data/ui/views.  Splunk tends to obfuscate their dashboard code so you'll likely have better luck viewing the panels by clicking on the "Open in Search" icon in the panel.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Why can you not use MC on mobile?

The searches you seek are all in $SPLUNK_HOME/etc/apps/splunk_monitoriing_console/default/savedsearches.conf.

---
If this reply helps you, Karma would be appreciated.

TheBravoSierra
Path Finder

I have access to view MC in Splunk Web but when I grant access for the same user to see it in mobile, they're unable to see it. Are you able to? Have you confirmed that is a supported functionality in Splunk Mobile? 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I'm unable to see the MC using Splunk Mobile, but that doesn't mean you can't copy the MC's searches into an app the mobile user can view.

---
If this reply helps you, Karma would be appreciated.
0 Karma

TheBravoSierra
Path Finder

In the location you specified above, I only see the saved searches. I don't see the searches for the dashboard panels. Would those be somewhere else?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Dashboards are in $SPLUNK_HOME/etc/apps/<app name>/default/data/ui/views.  Splunk tends to obfuscate their dashboard code so you'll likely have better luck viewing the panels by clicking on the "Open in Search" icon in the panel.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...