Splunk Search

How to refresh the list of servers in the SOS app

mataharry
Communicator

I removed a server from my cluster, and it still shows up in the dropdowns of the SOS app.
How is it maintained, can I reset the list ?

Tags (2)
1 Solution

yannK
Splunk Employee
Splunk Employee

The list of servers is maintained in a lookup in the SOS app.

1 - You can reset this lookup,
go to SOS > Lookups » Lookup table files
and remove .../splunk_servers_cache.csv

2- Then regenerate it using the search "sos_refresh_splunk_servers_cache" from the context of the SOS app.

By default the search is scheduled to run every 15 minutes, but append to the existing list, so you need to reset to clear servers.

View solution in original post

yannK
Splunk Employee
Splunk Employee

The list of servers is maintained in a lookup in the SOS app.

1 - You can reset this lookup,
go to SOS > Lookups » Lookup table files
and remove .../splunk_servers_cache.csv

2- Then regenerate it using the search "sos_refresh_splunk_servers_cache" from the context of the SOS app.

By default the search is scheduled to run every 15 minutes, but append to the existing list, so you need to reset to clear servers.

yannK
Splunk Employee
Splunk Employee

The full list if in $SPLUNK_HOME/etc/apps/sos/lookups
splunk_forwarders_cache.csv
splunk_instances_info.csv
splunk_servers_cache.csv

You can regenerate them using the searches :
[sos_refresh_splunk_forwarders_cache]
[sos_splunk_forwarders_info]
[sos_refresh_splunk_servers_cache]
[sos_splunk_instances_info]

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...