Splunk Search

Is there a way to automate diag to support?

daniel333
Builder

All,

Silly question - Is there a way to automate the sending of diags to Splunk support? I'd like to know they have current diags on file at anytime. If I can submit one nightly to them and they keep in a repo or something?

woodcock
Esteemed Legend

The best way would be to open a P0 support case, which is code for Enhancement Request (ER) and in the body request such a feature but then, because these never go anywhere and never get closed, use the CLI arguments for the diag command to continuously attach diags to that case. Then any time you open a new case or whatever, you can just tell them to grab the latest diags from your never-ending ER.

0 Karma

anthonymelita
Contributor

I don't see this as being possible, or why Splunk would allow it. Your diag gets attached to a case, for the purpose of troubleshooting the issue that case.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...