Getting Data In

Is it possible to run 'splunk list monitor' for a universal forwarder (deployment client) remotely?

mfrost8
Builder

Hi. I've got some rather complex rules (at least to me) that I'm pushing out to a remote Windows universal forwarder that is a deployment client. I'd like to confirm that the files it's trying to watch line up with what the rules I wrote are (I think) telling it to do. Normally, I'd go onto the universal forwarder and run 'splunk list monitor' to see what the forwarder thinks it's monitoring. In this case, however, I don't have access to the universal forwarder host.

Of course I could, in theory, just look to see if events from the sources I want are coming in and that there are no events from sources I don't want. However, I don't actually know if all of these sources are generating events regularly. In other words, the absence of events from a particular source might not be unusual, but I'd still like to know if Splunk is watching that file anyway.

Is there any way to run 'splunk list monitor' or its equivalent through Splunk? Maybe some debugging flag I could turn on that would dump that to splunkd.log so I could see that via _internal from the universal forwarder?

While I can't get on the client to even see if events are going into specific logs that might not be having new events going into them, I could at least feel more confident if I knew that Splunk thought it was watching that file.

This is Splunk 6.2.1, by the way.

Thanks

0 Karma
1 Solution

MuS
Legend

Hi mfrost8,

take a look at the docs http://docs.splunk.com/Documentation/Splunk/6.2.1/Admin/AccessandusetheCLIonaremoteserver#CLI_comman... where you find a list of commands which are not usable from remote. Based on that list it should be possible to use it, if you did enable remote access before http://docs.splunk.com/Documentation/Splunk/6.2.1/Admin/AccessandusetheCLIonaremoteserver#Enable_rem...

Hope this helps ...

cheers, MuS

View solution in original post

MuS
Legend

Hi mfrost8,

take a look at the docs http://docs.splunk.com/Documentation/Splunk/6.2.1/Admin/AccessandusetheCLIonaremoteserver#CLI_comman... where you find a list of commands which are not usable from remote. Based on that list it should be possible to use it, if you did enable remote access before http://docs.splunk.com/Documentation/Splunk/6.2.1/Admin/AccessandusetheCLIonaremoteserver#Enable_rem...

Hope this helps ...

cheers, MuS

mfrost8
Builder

Thanks very much. I think this was some functionality that slipped in during some release that I never knew about. This solved my problem.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...