Splunk Enterprise

Schedule or Auto-trigger blacklist

michaeler
Communicator

Every month when software updates go out, my Enterprise deployment exceeds the license. I get overloaded with Event Code 4663. After the first time, I just added it to the blacklist in inputs.conf and problem solved.

I'd like to leave that EventCode active and only disable it when the majority of systems are updating. I know I can do this manually but am trying to find if there is a way to automatically enable the blacklist based on date? Or to set a trigger based on a specific series of event codes that indicate software updates?

If anyone has tried this before I'm very curious if there's a solution?

0 Karma

venkatasri
SplunkTrust
SplunkTrust

@michaeler Nope its just an idea!

0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @michaeler 

You can schedule an Alert to monitor when updates starts based on specific EventCode or Pattern in logs the alerts 'alert Action' shall be a script which in turn change the blacklist settings of inputs conf which further needs to be pushed to windows UF clients. 

As the script gets executed locally on SH's it shall be able to reach out your Deployment Server where your inputs conf exist to modify through SSH or if you SH Deployer and DeploymentServer are co-located it would be easier.

Hope this helps!

0 Karma

michaeler
Communicator

Sounds like a reasonable solution. Have you done this before or just an idea? If you have done it before, any chance you could share the script with me?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...