Splunk Enterprise

How to recreate cpu memory usage searches?

TheBravoSierra
Path Finder

Because we are unable to use the monitoring console in Splunk Mobile, I would like to create our own monitoring console dashboard of sorts. Beginning with these searches, status, cpu usage, and memory usage of indexers and search heads. Does anyone have these searches available or know where I can locate them?

See attached screenshot for example.

Thanks

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Dashboards are in $SPLUNK_HOME/etc/apps/<app name>/default/data/ui/views.  Splunk tends to obfuscate their dashboard code so you'll likely have better luck viewing the panels by clicking on the "Open in Search" icon in the panel.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Why can you not use MC on mobile?

The searches you seek are all in $SPLUNK_HOME/etc/apps/splunk_monitoriing_console/default/savedsearches.conf.

---
If this reply helps you, Karma would be appreciated.

TheBravoSierra
Path Finder

I have access to view MC in Splunk Web but when I grant access for the same user to see it in mobile, they're unable to see it. Are you able to? Have you confirmed that is a supported functionality in Splunk Mobile? 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I'm unable to see the MC using Splunk Mobile, but that doesn't mean you can't copy the MC's searches into an app the mobile user can view.

---
If this reply helps you, Karma would be appreciated.
0 Karma

TheBravoSierra
Path Finder

In the location you specified above, I only see the saved searches. I don't see the searches for the dashboard panels. Would those be somewhere else?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Dashboards are in $SPLUNK_HOME/etc/apps/<app name>/default/data/ui/views.  Splunk tends to obfuscate their dashboard code so you'll likely have better luck viewing the panels by clicking on the "Open in Search" icon in the panel.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...