Recently, I fixed a malfunctioning email from Splunk. It included a PDF of a dashboard, “a scheduled PDF.” The dashboard wasn’t documented...
Collecting Data from ServiceNow in Splunk
Let's discuss how to collect data from your ServiceNow instance in Splunk. First, what is ServiceNow? ServiceNow is a maker of service management software that can be on-prem or in the cloud. Organizational use of ServiceNow ranges from standard IT help desk ticketing systems to legal service management. These organizations may want to collect data from their ServiceNow instance for security auditing or operational awareness of their deployment. ServiceNow exposes a REST API that can be used to extract this data.
Scenario
In...
Event Sampling - Splunk 6.4 Feature
A Direct Migration of WordPress to Drupal 8
Migrations from WordPress to Drupal are required when customers are standardizing on Drupal to ease institutional IT staffing requirements, or they just want the many additional customization capabilities built into Drupal. Here is how to migrate your WordPress data directly into Drupal 8 using the Migrate API.
Here is one workflow to get started quickly …
1. Setup your D8 site (drupal-8-0-5) locally. This blog post assumes your WP site is already setup on your local environment....
Monitoring Frozen Data Storage in Splunk
Frozen Wasteland
In this post, I'd like to visit the "Siberia" of Splunk data or frozen (archived) storage. For all other types of data besides frozen, you can get insight on your Splunk data at the index and bucket level by using the "dbinspect" command or apps like "Fire Brigade." However, because frozen data "lives" outside of the world of Splunk, there's no way to get insight on that data via Splunk. Therefore, I will outline a solution for creating a scripted input to send metrics to Splunk which can then be used for reporting.
Create the...
How to generate 1 TB of data for Splunk Performance Testing
HOW TO GENERATE 1 TB OF DATA FOR SPLUNK PERFORMANCE TESTING
INTRODUCTION
Splunk, a leader in Event Management provides insight into your business’s machine-generated log data. Splunk enables you to make sense of your business, make smart decisions and initiate corrective actions.
Processing Big Data is by no means a small feat. The ability to scale Splunk to accommodate and grow with your business is key to providing reliable and accurate information. Splunk provides insight into your...
Integrating External Asset Databases with the Splunk App for Enterprise Security
Overview
In this post I'd like to cover an approach for integrating an external asset database with the Splunk App for Enterprise Security (ES). This post is relevant for people just starting out with ES or who have used it for a while and want to improve the integration of their assets information with the application.
For those wondering what an assets list is in the context of ES, it's a list containing information (such as...
Red Hat Storage Server, an Innovative Hybrid Storage Solution for Big Data
Big Data surrounds us all, in some shape or form. Typically Big Data (billions or trillions of vast and complex records) is so large, that it requires new and powerful computational resources to process and store. These gigantic sets of data can be analyzed to comprehend patterns, associations, trends, and statistics that help better understand user experience, human behavior, interactions, engagement, etc.
Big Data analysis, such as the services offered by our Function1 Operational Intelligence team, can be provided for a range of industries including but not limited to: financial...
Accelerated Data Models in a Distributed Splunk Environment
Splunk v6.0.1 is packed with new features that enhance the user experience and can provide useful, lightning fast reports. For a full overview of the new features check out this link: Splunk 6!
One of the new features that provide users the ability to build exceptionally fast reports is data models. Users can use the structure provided by the data models to create pivot tables, all without knowing Splunk’s search language. Pivot users select the data model they are interested in, then point and click their...
Off the beaten path - Splunk search head pooling without search head pooling?? Its possible...
Recently I was working with a client that was Splunk savvy and they wanted to try to implement something that was, what I would consider, off the beaten path.
Here is the challenge:
This client was looking for a way to be able to take advantage of having multiple search heads for high resource availability and resiliency, without taking a hit on performance. One approach to go about providing high availability and resiliency of search heads is to use a Splunk feature called...