Splunk Enterprise

Schedule or Auto-trigger blacklist

michaeler
Communicator

Every month when software updates go out, my Enterprise deployment exceeds the license. I get overloaded with Event Code 4663. After the first time, I just added it to the blacklist in inputs.conf and problem solved.

I'd like to leave that EventCode active and only disable it when the majority of systems are updating. I know I can do this manually but am trying to find if there is a way to automatically enable the blacklist based on date? Or to set a trigger based on a specific series of event codes that indicate software updates?

If anyone has tried this before I'm very curious if there's a solution?

0 Karma

venkatasri
SplunkTrust
SplunkTrust

@michaeler Nope its just an idea!

0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @michaeler 

You can schedule an Alert to monitor when updates starts based on specific EventCode or Pattern in logs the alerts 'alert Action' shall be a script which in turn change the blacklist settings of inputs conf which further needs to be pushed to windows UF clients. 

As the script gets executed locally on SH's it shall be able to reach out your Deployment Server where your inputs conf exist to modify through SSH or if you SH Deployer and DeploymentServer are co-located it would be easier.

Hope this helps!

0 Karma

michaeler
Communicator

Sounds like a reasonable solution. Have you done this before or just an idea? If you have done it before, any chance you could share the script with me?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...