Splunk Search

Splunk query to get the inputs.conf on the deployment server for specific apps

Naa_Win
Path Finder

I know that rest calls don't cover the deployment server apps as they are not memory resident. But is there any way we can monitor Deployment Server which saves the output somewhere and we can monitor that to splunk ?

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

DS is not aware of the structure and functionality of deployment apps. What is your use case? What do you want to achieve?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Naa_Win ,

it's always a best practice that all the Splunk Servers (so also DS) send their logs to the Indexers.

So you could create an input on the DS that monitors the files in the /opt/splunk/etc/deployment-apps folder, so they are indexed.

Then you could display them in a custom dashboard, but it's all to develop, I don't know anything already existent.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...