Splunk Search

Verifying Configuration Through Splunk Web

michaeloleary
Path Finder

Hi Folks,

I'm trying to see if I can verify the configuration of any deployment applications via Splunk web. Currently administrators are making changes to a deployment application but the change is not visible to the users of Splunk when integrating new devices/syslogs etc. For instance if I change the following file.

/opt/splunk/etc/deployment-apps/test-app/local/inputs.conf

Users will not be able to see the change without SSH-ing into the deployment server and cat-ing the configuration file manually, I'd like to avoid giving users cli access where possible. Currently users in the organisation are unable to verify the configuration of the inputs.conf. I know in S.O.S, Splunk uses btool to verify the configuration of the inputs files under the apps directory. Is there something similar that can do the job described above with the deployment apps? Maybe btool can achieve this but I've had very little luck at the moment. Any help would be greatly appreciated. Thanks folks.

Tags (1)
0 Karma

MuS
SplunkTrust
SplunkTrust

hi michaeloleary

you could use the same btool from S.o.S. for this, it is a python script in etc/apps/sos/bin/ called btool.py. Copy it to etc/apps/<yourapp>/bin and add btool.py to commands.conf in etc/apps/<yourapp>/default/.

After that you can run the following query to get the inputs on your splunk:

 | btool inputs 

hope this helps

cheers,

MuS

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Index This | What has goals but no motivation?

June 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...