Splunk Search

Splunk query to get the inputs.conf on the deployment server for specific apps

Naa_Win
Path Finder

I know that rest calls don't cover the deployment server apps as they are not memory resident. But is there any way we can monitor Deployment Server which saves the output somewhere and we can monitor that to splunk ?

0 Karma

PickleRick
SplunkTrust
SplunkTrust

DS is not aware of the structure and functionality of deployment apps. What is your use case? What do you want to achieve?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Naa_Win ,

it's always a best practice that all the Splunk Servers (so also DS) send their logs to the Indexers.

So you could create an input on the DS that monitors the files in the /opt/splunk/etc/deployment-apps folder, so they are indexed.

Then you could display them in a custom dashboard, but it's all to develop, I don't know anything already existent.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...