All Apps and Add-ons

Adding Windows monitors via Linux CLI

davideddleman
New Member

Our central Splunk server is Linux, running (now) the latest as I suspected there was a bug involved in this situation. I've deployed the Windows universal forwarder to a bunch of Windows Server 2008 machines, and due to a known bug in the installer (as shown to me by Splunk support) they had to be installed with no options, and configured after. Since there are a lot of machines, I'm attempting to automate everything.

Whenever I attempt to add in a monitor via the splunk command on our Linux server, I get an error. This is what it is:
splunk add monitor -uri https://:8089 -auth
In handler 'monitor': Parameter name: Path does not exist.

It sounds like the monitor is only validated against what's valid for the local OS. Is this expected behavior or a bug? I've attempted the usual UNIX tricks -- encased the path in quotes, escaped the special characters, etc.

0 Karma

lukejadamec
Super Champion

Hi lukejadamec, this is not completely true .... you can use the CLI from the indexer to add a monitor on the forwarder. It's just not allowed by default - you must enable allowRemoteLogin in the server.conf of the forwarder. After that you can add a monitor remotely. BTW, with exception of the start, stop, restart, status and version command, all that control the splunkd, you can run all CLI commands remotely.

lukejadamec
Super Champion

Thanks MuS.

MuS
Legend

Hi lukejadamec, this is not completely true .... you can use the CLI from the indexer to add a monitor on the forwarder. It's just not allowed by default - you must enable allowRemoteLogin in the server.conf of the forwarder. After that you can add a monitor remotely. BTW, with exception of the start, stop, restart, status and version command, all that control the splunkd, you can run all CLI commands remotely.

davideddleman
New Member

Note that I'm not entering the path as . That's just how the Answers section formatted it.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...