All Apps and Add-ons

Splunk For Nagios hostperf and serviceperf Log Format

ivedasolutions
New Member

I am attempting to setup Splunk for Nagios and I am having quite a few problems. First off, even with MK Livestatus, check_mk and the check_mk-agent installed, the Livestatus dashboards do not work. All I get is N/A and then after a few moments the N/A's are replaced with <<<\check_mk>>>. When trying to troubleshoot and dissect some of the queries being used for checking up hosts and down hosts from the logs that are being sent to Splunk from Nagios, they return nothing. My guess is that the format of the hostperf and serviceperf log files are wrong however, I have not been able to find ANYWHERE that tells me what format these need to be in. All of the documentation I have found is seriously lacking in configuring Splunk for Nagios. Any additional help is most appreciated.

Thank you!

0 Karma

lukeh
Contributor

Hi,

The definitions for the host and service performance logs are available at the Documentation link here:

http://apps.splunk.com/app/352/

Which version of the following apps are you running in your environment:

Splunk

Splunk for Nagios

Nagios

MK Livestatus

BTW, Splunk for Nagios 3.0.0 has been released and is much easier to configure for MK Livestatus, so please upgrade first 🙂

All the best,

Luke 🙂

0 Karma

ivedasolutions
New Member

Bump...

No one has any ideas what is going on here?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...