- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/6b305/6b30587f4930d3fb5a3b702327abd87164ea90b6" alt="somesoni2 somesoni2"
Hi All,
I am trying to write a search to get values from the configuration file. An example of it will be to the minFreeSpace property from server.conf (under diskUsage stanza).
So far I have written:
| rest /services/properties/server/diskUsage
This gives me list of properties defined under diskUsage stanza, but value for each property is not shown.
"author" "id "published" "splunk_server" "title" "updated"
"blank" "<someurl>diskUsage/minFreeSpace" "blank" "myhost" "minFreeSpace" "somedate"
"blank" "<someurl>diskUsage/pollingFrequency" "blank" "myhost" "pollingFrequency" "somedate"
"blank" "<someurl>diskUsage/pollingTimerFrequency" "blank" "myhost" "pollingTimerFrequency" "somedate"
Could anyone help me how to get the values too.
I tried with "|REST /services/properties/server/diskUsage/minFreeSpace" but it shows no result.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I opened a support ticket on a similar issue. Until the latest release (v6.0.2) the rest search command would not return text value elements included in the response. This behavior is now fixed.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I opened a support ticket on a similar issue. Until the latest release (v6.0.2) the rest search command would not return text value elements included in the response. This behavior is now fixed.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/6b305/6b30587f4930d3fb5a3b702327abd87164ea90b6" alt="somesoni2 somesoni2"
I was using Splunk 5.0.5 but planning to upgrade to Splunk 6.x. Thanks for the update.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
I can't test this right now, but you might be trapped in namespace hell. Give it a shot to play around with the various servicesNS options.
Your second URL with the stanza and key should be the only properties endpoint to actually report a value, once namespace stuff is sorted out.
As an alternative, take a look at the configs/conf-server endpoint.
data:image/s3,"s3://crabby-images/a266d/a266d0c80c12793a952b209c17cc3de41b17fc89" alt=""