Splunk Search

Is there a way to automate diag to support?

daniel333
Builder

All,

Silly question - Is there a way to automate the sending of diags to Splunk support? I'd like to know they have current diags on file at anytime. If I can submit one nightly to them and they keep in a repo or something?

woodcock
Esteemed Legend

The best way would be to open a P0 support case, which is code for Enhancement Request (ER) and in the body request such a feature but then, because these never go anywhere and never get closed, use the CLI arguments for the diag command to continuously attach diags to that case. Then any time you open a new case or whatever, you can just tell them to grab the latest diags from your never-ending ER.

0 Karma

anthonymelita
Contributor

I don't see this as being possible, or why Splunk would allow it. Your diag gets attached to a case, for the purpose of troubleshooting the issue that case.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...