Re: Splunk Integration Question...
"Frost, Mark {BIS}" <[email protected]> Tue, 10 Sep 2013 17:10:00 +0000
| Newsgroups | gmane.network.nagios.user |
|---|---|
| Message-ID | <[email protected]> |
--===============3985722776991225315== Content-Language: en-US Content-Type: multipart/alternative; boundary="_000_3FC36F2C7B96D444A1138066E952D2B60DF744PEPWMC00171corppe_" --_000_3FC36F2C7B96D444A1138066E952D2B60DF744PEPWMC00171corppe_ Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Sean, Can you describe what you're doing for Splunk integration with Nagios? I'= ve used Splunk with Nagios in a couple different ways, but I'm not aware of= any single standard for doing so. Originally, I just had Splunk run a scheduled search, which would trigger a= script which sent a passive check result back to a Nagios service via NSCA= . That way - having Nagios process passive check results from Splunk - wa= s the only way I could see to do that. Recently, I played around a bit with writing scripts that made use of Splun= k's REST API so the checks could be run as active checks from Nagios. (I a= lways prefer active checks). I set this up for only one check, but once I= got it working it worked pretty well. As a side note, I'm still a little on the fence about whether or not I real= ly want to have Nagios find problems through Splunk and then alert on them = or have Splunk find an alert on them directly without using Nagios at all..= . Are you referring to another way of making Splunk and Nagios talk together? Mark From: Sean Alderman [mailto:[email protected]] Sent: Monday, September 09, 2013 1:12 PM To: [email protected] Subject: [Nagios-users] Splunk Integration Question... Greetings, I was hoping I might find someone who's got the splunk integration active= ly working. I'm running Nagios Core (via EPEL) and Splunk 5.0.3 on OracleL= inux 6.4. When I edit cgi.cfg and enable splunk integration, then set the splunk U= RL to https://<mysplunkserver>:8000/en-US/app/search/flastimeline<https://%= 3cmysplunkserver%3e:8000/en-US/app/search/flastimeline>, I notice the nagio= s URLs look like: https://<mysplunkserver>:8000/en-US/app/flashtimeline?q= =3Dsearch%20test1.udayton.edu<http://20test1.udayton.edu>%20<nagios plugin = check>. I have two questions... * Is there a way I can make nagios use the hostname only, not the F= QDN? We use short names in splunk so we don't a mix of fqdn and short name= s since we use both forwarders and syslog as input. * What data is this query looking for, is it expected that I should= have my nagios log in splunk? The <nagios plugin check> in the query does= n't seem useful to me, unless there's splunk data specifically tied to that= check, and I'm hoping someone could provide an example. Kind regards, -- Sean M. Alderman Senior Engineer, UDit Systems Integration and Engineering University of Dayton --_000_3FC36F2C7B96D444A1138066E952D2B60DF744PEPWMC00171corppe_ Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable <html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr= osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" = xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:= //www.w3.org/TR/REC-html40"> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"= > <meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)"> <style><!-- /* Font Definitions */ @font-face {font-family:Wingdings; panose-1:5 0 0 0 0 0 0 0 0 0;} @font-face {font-family:Wingdings; panose-1:5 0 0 0 0 0 0 0 0 0;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;} @font-face {font-family:Tahoma; panose-1:2 11 6 4 3 5 4 4 2 4;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0in; margin-bottom:.0001pt; font-size:12.0pt; font-family:"Times New Roman","serif";} a:link, span.MsoHyperlink {mso-style-priority:99; color:blue; text-decoration:underline;} a:visited, span.MsoHyperlinkFollowed {mso-style-priority:99; color:purple; text-decoration:underline;} span.EmailStyle17 {mso-style-type:personal-reply; font-family:"Calibri","sans-serif"; color:#1F497D;} .MsoChpDefault {mso-style-type:export-only; font-family:"Calibri","sans-serif";} @page WordSection1 {size:8.5in 11.0in; margin:1.0in 1.0in 1.0in 1.0in;} div.WordSection1 {page:WordSection1;} /* List Definitions */ @list l0 {mso-list-id:1901165503; mso-list-template-ids:1371975592;} @list l0:level1 {mso-level-number-format:bullet; mso-level-text:\F0B7; mso-level-tab-stop:.5in; mso-level-number-position:left; text-indent:-.25in; mso-ansi-font-size:10.0pt; font-family:Symbol;} @list l0:level2 {mso-level-number-format:bullet; mso-level-text:o; mso-level-tab-stop:1.0in; mso-level-number-position:left; text-indent:-.25in; mso-ansi-font-size:10.0pt; font-family:"Courier New"; mso-bidi-font-family:"Times New Roman";} @list l0:level3 {mso-level-number-format:bullet; mso-level-text:\F0A7; mso-level-tab-stop:1.5in; mso-level-number-position:left; text-indent:-.25in; mso-ansi-font-size:10.0pt; font-family:Wingdings;} @list l0:level4 {mso-level-number-format:bullet; mso-level-text:\F0A7; mso-level-tab-stop:2.0in; mso-level-number-position:left; text-indent:-.25in; mso-ansi-font-size:10.0pt; font-family:Wingdings;} @list l0:level5 {mso-level-number-format:bullet; mso-level-text:\F0A7; mso-level-tab-stop:2.5in; mso-level-number-position:left; text-indent:-.25in; mso-ansi-font-size:10.0pt; font-family:Wingdings;} @list l0:level6 {mso-level-number-format:bullet; mso-level-text:\F0A7; mso-level-tab-stop:3.0in; mso-level-number-position:left; text-indent:-.25in; mso-ansi-font-size:10.0pt; font-family:Wingdings;} @list l0:level7 {mso-level-number-format:bullet; mso-level-text:\F0A7; mso-level-tab-stop:3.5in; mso-level-number-position:left; text-indent:-.25in; mso-ansi-font-size:10.0pt; font-family:Wingdings;} @list l0:level8 {mso-level-number-format:bullet; mso-level-text:\F0A7; mso-level-tab-stop:4.0in; mso-level-number-position:left; text-indent:-.25in; mso-ansi-font-size:10.0pt; font-family:Wingdings;} @list l0:level9 {mso-level-number-format:bullet; mso-level-text:\F0A7; mso-level-tab-stop:4.5in; mso-level-number-position:left; text-indent:-.25in; mso-ansi-font-size:10.0pt; font-family:Wingdings;} ol {margin-bottom:0in;} ul {margin-bottom:0in;} --></style><!--[if gte mso 9]><xml> <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" /> </xml><![endif]--><!--[if gte mso 9]><xml> <o:shapelayout v:ext=3D"edit"> <o:idmap v:ext=3D"edit" data=3D"1" /> </o:shapelayout></xml><![endif]--> </head> <body lang=3D"EN-US" link=3D"blue" vlink=3D"purple"> <div class=3D"WordSection1"> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca= libri","sans-serif";color:#1F497D">Sean,<o:p></o:p></span></= p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca= libri","sans-serif";color:#1F497D"><o:p> </o:p></span><= /p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca= libri","sans-serif";color:#1F497D">Can you describe what you= ’re doing for Splunk integration with Nagios? I’ve = used Splunk with Nagios in a couple different ways, but I’m not aware= of any single standard for doing so.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca= libri","sans-serif";color:#1F497D"><o:p> </o:p></span><= /p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca= libri","sans-serif";color:#1F497D">Originally, I just had Sp= lunk run a scheduled search, which would trigger a script which sent a pass= ive check result back to a Nagios service via NSCA. That way – having Nagios process passive check results from Splunk –= ; was the only way I could see to do that.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca= libri","sans-serif";color:#1F497D"><o:p> </o:p></span><= /p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca= libri","sans-serif";color:#1F497D">Recently, I played around= a bit with writing scripts that made use of Splunk’s REST API so the= checks could be run as active checks from Nagios. (I always prefer active checks). I set this up for only one check, but o= nce I got it working it worked pretty well.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca= libri","sans-serif";color:#1F497D"><o:p> </o:p></span><= /p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca= libri","sans-serif";color:#1F497D">As a side note, I’m= still a little on the fence about whether or not I really want to have Nag= ios find problems through Splunk and then alert on them or have Splunk find an alert on them directly without using Nagios at all…<o= :p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca= libri","sans-serif";color:#1F497D"><o:p> </o:p></span><= /p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca= libri","sans-serif";color:#1F497D">Are you referring to anot= her way of making Splunk and Nagios talk together?<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca= libri","sans-serif";color:#1F497D"><o:p> </o:p></span><= /p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca= libri","sans-serif";color:#1F497D">Mark<o:p></o:p></span></p= > <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca= libri","sans-serif";color:#1F497D"><o:p> </o:p></span><= /p> <p class=3D"MsoNormal" style=3D"margin-left:.5in"><b><span style=3D"font-si= ze:10.0pt;font-family:"Tahoma","sans-serif"">From:</spa= n></b><span style=3D"font-size:10.0pt;font-family:"Tahoma","= sans-serif""> Sean Alderman [mailto:[email protected]] <br> <b>Sent:</b> Monday, September 09, 2013 1:12 PM<br> <b>To:</b> [email protected]<br> <b>Subject:</b> [Nagios-users] Splunk Integration Question...<o:p></o:p></s= pan></p> <p class=3D"MsoNormal" style=3D"margin-left:.5in"><o:p> </o:p></p> <div> <div> <div> <div> <p class=3D"MsoNormal" style=3D"margin-left:.5in">Greetings,<o:p></o:p></p> </div> <p class=3D"MsoNormal" style=3D"mso-margin-top-alt:0in;margin-right:0in;mar= gin-bottom:12.0pt;margin-left:.5in"> I was hoping I might find someone who's got the splunk integration a= ctively working. I'm running Nagios Core (via EPEL) and Splunk 5.0.3 = on OracleLinux 6.4.<o:p></o:p></p> </div> <p class=3D"MsoNormal" style=3D"margin-left:.5in"> When I edit = cgi.cfg and enable splunk integration, then set the splunk URL to <a href=3D"https://%3cmysplunkserver%3e:8000/en-US/app/search/flastimeline"= >https://<mysplunkserver>:8000/en-US/app/search/flastimeline</a>, I n= otice the nagios URLs look like: https://<mysplunkserver>:8000/en-US/= app/flashtimeline?q=3Dsearch%<a href=3D"http://20test1.udayton.edu">20test1= .udayton.edu</a>%20<nagios plugin check>. I have two questions...<o:p></o:p></p> <p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a= lt:auto;margin-left:1.0in;text-indent:-.25in;mso-list:l0 level1 lfo1"> <![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol"><s= pan style=3D"mso-list:Ignore">·<span style=3D"font:7.0pt "Times= New Roman""> </span></span></span><![endif]>Is there a way I can make nagios use the hos= tname only, not the FQDN? We use short names in splunk so we don't a = mix of fqdn and short names since we use both forwarders and syslog as inpu= t.<o:p></o:p></p> <p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a= lt:auto;margin-left:1.0in;text-indent:-.25in;mso-list:l0 level1 lfo1"> <![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol"><s= pan style=3D"mso-list:Ignore">·<span style=3D"font:7.0pt "Times= New Roman""> </span></span></span><![endif]>What data is this query looking for, is it e= xpected that I should have my nagios log in splunk? The <nagios pl= ugin check> in the query doesn't seem useful to me, unless there's splun= k data specifically tied to that check, and I'm hoping someone could provide an example.<br clear=3D"all"> <o:p></o:p></p> </div> <div> <div> <div> <div> <p class=3D"MsoNormal" style=3D"margin-left:.5in">Kind regards,<o:p></o:p><= /p> </div> <div> <p class=3D"MsoNormal" style=3D"margin-left:.5in">-- <o:p></o:p></p> <div> <p class=3D"MsoNormal" style=3D"mso-margin-top-alt:0in;margin-right:0in;mar= gin-bottom:12.0pt;margin-left:.5in"> Sean M. Alderman<br> Senior Engineer, UDit Systems Integration and Engineering<br> University of Dayton<o:p></o:p></p> </div> </div> </div> </div> </div> </div> </div> </body> </html> --_000_3FC36F2C7B96D444A1138066E952D2B60DF744PEPWMC00171corppe_-- --===============3985722776991225315== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline ------------------------------------------------------------------------------ How ServiceNow helps IT people transform IT departments: 1. Consolidate legacy IT systems to a single system of record for IT 2. Standardize and globalize service processes across IT 3. Implement zero-touch automation to replace manual, redundant tasks http://pubads.g.doubleclick.net/gampad/clk?id=51271111&iu=/4140/ostg.clktrk --===============3985722776991225315== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Nagios-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/nagios-users ::: Please include Nagios version, plugin version (-v) and OS when reporting any issue. ::: Messages without supporting info will risk being sent to /dev/null --===============3985722776991225315==--