All Apps and Add-ons

Can we analyze diag file with S.o.S by ourselves ?

sunrise
Contributor

We can set S.o.S on our UAT environment, but cannot set on production environment.
We want to analyze diag file getting from production environment to use S.o.S in UAT.
Can I do that ?
Can S.o.S allow us to analyze other environment diag file ?

1 Solution

hexx
Splunk Employee
Splunk Employee

The S.o.S app is not built to analyze data contained in diags, its searches are specifically targeted at live data in the Splunk internal indexes (_internal, _audit) and in its own index (sos).

View solution in original post

hexx
Splunk Employee
Splunk Employee

If you have attended a partner shadowing program with Splunk Support, you can reach out to the Support engineers that you worked with and request a copy of the UnDiag app, which does precisely what you want.

0 Karma

sunrise
Contributor

Actually, I'm working for the business partner of Splunk. I got the diag file from the end user to troubleshoot the issue. So I hope S.o.S enable to analyze at non-live data. .

0 Karma

hexx
Splunk Employee
Splunk Employee

Out of curiosity, what is the specific reason that prevents you from using the S.o.S app in your production environment?

hexx
Splunk Employee
Splunk Employee

The S.o.S app is not built to analyze data contained in diags, its searches are specifically targeted at live data in the Splunk internal indexes (_internal, _audit) and in its own index (sos).

Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...