Deployment Architecture

Programatically adding and removing mounts for indexing

msacks
Explorer

I would like to know how I might go about automatically adding and removing log mounts for this environment, and making sure the corresponding data sources that I am changing to be indexed also update a specific custom application that encompasses that mount as well.

Tags (2)
0 Karma

MuS
Legend

Hi msacks

yes, you can do this with the REST API, read more here: RESTconfigurations

cheers

0 Karma

msacks
Explorer

I second gkanapathy comment. It's really unclear what you are trying >to do, and more importantly, what you are trying to do with splunk.

Programmatically update my Splunk configurations using an API.

0 Karma

Lowell
Super Champion

No response. I'm giving a down vote.

0 Karma

Lowell
Super Champion

I second gkanapathy comment. It's really unclear what you are trying to do, and more importantly, what you are trying to do with splunk. You can click the "edit" button under your question and add some additional detail.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

I'm confused about what you're looking for. Splunk doesn't really take care of mounting or unmounting filesystems, and I'm not sure what you mean by "update a specific application". You mean if you change out a filesystem and path, you have to update the inputs.conf?

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...