All Apps and Add-ons

Can the website monitoring app be used in a SH cluster?

brent_weaver
Builder

I am specifically referring to app https://splunkbase.splunk.com/app/1493/ in this question. I am also wondering what other catches this may have, most namely can it run in a SH cluster.

0 Karma

steven_winslow
Explorer

When you configure the Data Inputs for your monitored sites, check the box for 'More settings' and you'll be able to select the destination index of your choosing. This is for each input/site that you add. Depending on your environment, you may also want to edit the searches on the built in dashboards to start with index=index_name if you change from the default.

You can use the app on all your SH's, but you'll want to configure the inputs on just 1 server. Only one needs to send data to your indexer(s). All of them can view it.

brent_weaver
Builder

I did that and got the following error when trying to configure through data inputs:

Encountered the following error while trying to save: Validation for scheme=web_ping failed: The script returned with exit status 1.

Ultimately I need to figure this out in .conf files. I do not have the UI to configure things so I would imagine like most things splunk, I can build a conf file to make this all happen???

Thanks!

0 Karma

season88481
Contributor

Seems like you have to explicitly select an index for the Website input.

I went to 'advance setting', instead of using default index, simply give it any available index. It should work.

0 Karma

steven_winslow
Explorer

Here's an example entry for a Data Input configured in an inputs.conf file.

[web_ping://CNN]
index = website_monitoring
interval = 1
source = CNN
title = CNN
url = http://www.cnn.com/
user_agent = Splunk Website Monitoring (+https://splunkbase.splunk.com/app/1493/)
0 Karma

brent_weaver
Builder

Also how do I redirect these events to a specific index?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...