Integrations/splunk/splunk.splunk pimB: Difference between revisions
imported>Cmace (copied from internal) |
imported>Jason.nicholls m (moved Splunk pimB to integrations/splunk/splunk.splunk pimB) |
||
(4 intermediate revisions by 2 users not shown) | |||
Line 1: | Line 1: | ||
{{DISPLAYTITLE:Splunk pimB}} | |||
[[Category:Integrations]] | |||
This page documents the enPortal integration for Splunk. | This page documents the enPortal integration for Splunk. | ||
* <b>Vendor</b>: Splunk | * <b>Vendor</b>: Splunk | ||
* <b>Product</b>: Splunk | * <b>Product</b>: Splunk | ||
* <b>Supported Version(s)</b>: | * <b>Supported Version(s)</b>: 4.3.4 | ||
* <b>Name of enPortal Integration Package</b>: splunk.splunk_pimB | * <b>Name of enPortal Integration Package</b>: splunk.splunk_pimB | ||
* <b>Required enPortal Version</b>: 4.6.1 and above | * <b>Required enPortal Version</b>: 4.6.1 and above | ||
Line 42: | Line 44: | ||
# Click the <b>Start</b> button to load the PIM into the system | # Click the <b>Start</b> button to load the PIM into the system | ||
# Confirm that the following message is displayed: "Import completed; loaded the following file(s): load_splunk.splunk_pimB.txt" | # Confirm that the following message is displayed: "Import completed; loaded the following file(s): load_splunk.splunk_pimB.txt" | ||
# Under the <b>Advanced</b> tab, select <b>Explore System</b> | |||
# Navigate to the /Directory/system/proxy/ folder and locate the “Manage Proxy” channel | |||
# Right-click on the “Manage Proxy” channel and select <b>Open</b> to launch the channel | |||
# In the Manage Proxy tool, click “Reset All” | |||
# Refresh the browser | |||
== Integration Details == | == Integration Details == | ||
Line 92: | Line 98: | ||
== Splunk Upgrades == | == Splunk Upgrades == | ||
=== Upgrading from an older version of Splunk === | === Upgrading from an older version of Splunk to Version 4.3.4 === | ||
Older versions of Splunk are not supported by this PIM, so this upgrade path is not supported. | Older versions of Splunk are not supported by this PIM, so this upgrade path is not supported. | ||
=== Upgrading Splunk to a newer version === | === Upgrading Splunk from Version 4.3.4 to a newer version === | ||
Perform the following steps when the Splunk server is upgraded to a newer version of Splunk: | Perform the following steps when the Splunk server is upgraded to a newer version of Splunk: | ||
# Check the AppBoard/enPortal PIM online documentation to see if the new Splunk version is supported by the existing splunk.splunk_pimB PIM | # Check the AppBoard/enPortal PIM online documentation to see if the new Splunk version is supported by the existing splunk.splunk_pimB PIM. | ||
## To test if the new Splunk version is supported by the existing PIM that you have installed, perform the following steps: | ## To test if the new Splunk version is supported by the existing PIM that you have installed, perform the following steps: | ||
### Click on the <b>Applications</b> tab | ### Click on the <b>Applications</b> tab |
Latest revision as of 07:26, 25 July 2014
This page documents the enPortal integration for Splunk.
- Vendor: Splunk
- Product: Splunk
- Supported Version(s): 4.3.4
- Name of enPortal Integration Package: splunk.splunk_pimB
- Required enPortal Version: 4.6.1 and above
The following section documents supported platforms, installation, and configuration of the Splunk Product Integration Module on enPortal versions 5.0 and above.
Support Matrix
The following Operating System, Database, and Web Browser platforms are supported:
Operating System
Please see the list of supported Operating Systems on the System Requirements page.
Database
A special database is not required to implement this integration module. The AppBoard/enPortal database is used to store all configurations related to this integration module.
Web Browser
Please see the list of supported Web Browsers on the System Requirements page.
Installation
Perform the following steps to install the Splunk PIM:
- Install AppBoard/enPortal as detailed in the Installation documentation
- Download the file splunk.splunk_pimB.jar
- Start enPortal and login as an administrator
- User Name: administrator
- Password: administrator
- Domain: System
- Under the Advanced tab, select PIMImport
- Click the Browse... button
- Locate the Splunk package.jar file in the Open dialog
- Click the Start button to extract the files from the PIM .jar archive
- Under the Advanced tab, select XMLImport
- Click the Start button to load the PIM into the system
- Confirm that the following message is displayed: "Import completed; loaded the following file(s): load_splunk.splunk_pimB.txt"
- Under the Advanced tab, select Explore System
- Navigate to the /Directory/system/proxy/ folder and locate the “Manage Proxy” channel
- Right-click on the “Manage Proxy” channel and select Open to launch the channel
- In the Manage Proxy tool, click “Reset All”
- Refresh the browser
Integration Details
This sections provides special details for configuring the integration module after installation.
Channel Types
- Application - The main entrance points of Splunk, "gettingstarted" and "search".
- Search Application - The search application functions. They are SplunkTest, charting, dashboard_live, flashtimeline, index_status, index_status_health, indexing_volume, inputs_status, pdf_activity, scheduler_savedsearch, scheduler_status, scheduler_status_errors, scheduler_user_app, search_detail_activity, search_status, search_ui_activity, search_user_activity, splunkd_status, splunkweb_status
- Home - Channel that displays the top-level Home page of the Splunk application
- Proxy - Channel that is used by the system to display Splunk channels
Configuration
After installing the Splunk PIM, perform the following steps to configure access to the host Splunk server:
- Click on the Applications tab
- Right-click on the name "sample" in the row for splunk.splunk_pimB and select "Modify"
- Fill in the items in the Modify Application Wizard dialog:
- Select the protocol used to access your Splunk server (http or https)
- Change the host name from "changeme" to the hostname or ip address that will resolve to your Splunk server
- Change the port to the port number of your Splunk server
- Click "Save" to keep your changes
- Click on the Integrations tab
- In the Explorer, under Packages, expand the splunk.splunk_pimB tree and click on the Sample target. Confirm that the information you entered is displayed for your Splunk server
- Under the Sample target, click on the Home channel. A login prompt should be displayed.
- Log in using the same credentials you would use for accessing the Splunk application in a browser. Confirm that the Splunk Home page is displayed.
Create Channels
After installing the Splunk PIM and configuring access to the host Splunk server, perform the following steps to create channels to display Splunk content:
- Click on the Applications tab
- Right-click on the name "sample" in the row for splunk.splunk_pimB and select a channel type
- In the "Channel Name" box, enter the name you want to give to the new channel
- For "Channel Type", select "3rd Party Pims"
- Click Next
- Click Finish
- Click on the Integrations tab
- In the Explorer, under Packages, expand the splunk.splunk_pimB tree and click on the Sample target. Confirm that the new channel is listed along with the other sample channels
Repeat the above steps to create additional channels. Select a different Channel Type in step 2 to create a different type of channel.
Splunk Upgrades
Upgrading from an older version of Splunk to Version 4.3.4
Older versions of Splunk are not supported by this PIM, so this upgrade path is not supported.
Upgrading Splunk from Version 4.3.4 to a newer version
Perform the following steps when the Splunk server is upgraded to a newer version of Splunk:
- Check the AppBoard/enPortal PIM online documentation to see if the new Splunk version is supported by the existing splunk.splunk_pimB PIM.
- To test if the new Splunk version is supported by the existing PIM that you have installed, perform the following steps:
- Click on the Applications tab
- Right-click on the row for the old Splunk server and select "Modify"
- Update the protocol, host, and port to reference the server where the new version of Splunk is running
- If the new Splunk version is not supported by the existing PIM that you have installed, perform the following steps to upgrade the PIM:
- Download the new PIM version from the PIM download site
- Follow the steps in the Installation section above to install and configure the new PIM version
- Re-create all Splunk channels to reference the new PIM
- [Optional] Perform the steps outlined in the Uninstall section below to remove the old PIM from the system
- To test if the new Splunk version is supported by the existing PIM that you have installed, perform the following steps:
Uninstall
Perform the following steps to uninstall the splunk.splunk_pimB PIM:
- Click on the Integrations tab
- In the Explorer, under Packages, locate the splunk.splunk_pimB integration
- Right click on the integration name, and select "Delete"
- Click "Ok" to confirm that you want to delete the integration package