Re: Splunk Integration Question...

"Frost, Mark {BIS}" <[email protected]> Tue, 10 Sep 2013 17:10:00 +0000
Newsgroups gmane.network.nagios.user
Message-ID <[email protected]>
--===============3985722776991225315==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_3FC36F2C7B96D444A1138066E952D2B60DF744PEPWMC00171corppe_"

--_000_3FC36F2C7B96D444A1138066E952D2B60DF744PEPWMC00171corppe_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Sean,

Can you describe what you're doing for Splunk integration with Nagios?   I'=
ve used Splunk with Nagios in a couple different ways, but I'm not aware of=
 any single standard for doing so.

Originally, I just had Splunk run a scheduled search, which would trigger a=
 script which sent a passive check result back to a Nagios service via NSCA=
.   That way - having Nagios process passive check results from Splunk - wa=
s the only way I could see to do that.

Recently, I played around a bit with writing scripts that made use of Splun=
k's REST API so the checks could be run as active checks from Nagios.  (I a=
lways prefer active checks).   I set this up for only one check, but once I=
 got it working it worked pretty well.

As a side note, I'm still a little on the fence about whether or not I real=
ly want to have Nagios find problems through Splunk and then alert on them =
or have Splunk find an alert on them directly without using Nagios at all..=
.

Are you referring to another way of making Splunk and Nagios talk together?

Mark

From: Sean Alderman [mailto:[email protected]]
Sent: Monday, September 09, 2013 1:12 PM
To: [email protected]
Subject: [Nagios-users] Splunk Integration Question...

Greetings,
  I was hoping I might find someone who's got the splunk integration active=
ly working.  I'm running Nagios Core (via EPEL) and Splunk 5.0.3 on OracleL=
inux 6.4.
   When I edit cgi.cfg and enable splunk integration, then set the splunk U=
RL to https://<mysplunkserver>:8000/en-US/app/search/flastimeline<https://%=
3cmysplunkserver%3e:8000/en-US/app/search/flastimeline>, I notice the nagio=
s URLs look like: https://<mysplunkserver>:8000/en-US/app/flashtimeline?q=
=3Dsearch%20test1.udayton.edu<http://20test1.udayton.edu>%20<nagios plugin =
check>.  I have two questions...
*         Is there a way I can make nagios use the hostname only, not the F=
QDN?  We use short names in splunk so we don't a mix of fqdn and short name=
s since we use both forwarders and syslog as input.
*         What data is this query looking for, is it expected that I should=
 have my nagios log in splunk?  The <nagios plugin check> in the query does=
n't seem useful to me, unless there's splunk data specifically tied to that=
 check, and I'm hoping someone could provide an example.
Kind regards,
--
Sean M. Alderman
Senior Engineer, UDit Systems Integration and Engineering
University of Dayton

--_000_3FC36F2C7B96D444A1138066E952D2B60DF744PEPWMC00171corppe_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri","sans-serif";}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:1901165503;
	mso-list-template-ids:1371975592;}
@list l0:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l0:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:1.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l0:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l0:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l0:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l0:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l0:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l0:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Sean,<o:p></o:p></span></=
p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Can you describe what you=
&#8217;re doing for Splunk integration with Nagios?&nbsp;&nbsp; I&#8217;ve =
used Splunk with Nagios in a couple different ways, but I&#8217;m not aware=
 of any single
 standard for doing so.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Originally, I just had Sp=
lunk run a scheduled search, which would trigger a script which sent a pass=
ive check result back to a Nagios service via NSCA.&nbsp;&nbsp; That
 way &#8211; having Nagios process passive check results from Splunk &#8211=
; was the only way I could see to do that.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Recently, I played around=
 a bit with writing scripts that made use of Splunk&#8217;s REST API so the=
 checks could be run as active checks from Nagios.&nbsp; (I always
 prefer active checks).&nbsp;&nbsp; I set this up for only one check, but o=
nce I got it working it worked pretty well.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">As a side note, I&#8217;m=
 still a little on the fence about whether or not I really want to have Nag=
ios find problems through Splunk and then alert on them or have
 Splunk find an alert on them directly without using Nagios at all&#8230;<o=
:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Are you referring to anot=
her way of making Splunk and Nagios talk together?<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Mark<o:p></o:p></span></p=
>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal" style=3D"margin-left:.5in"><b><span style=3D"font-si=
ze:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;">From:</spa=
n></b><span style=3D"font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;=
sans-serif&quot;"> Sean Alderman [mailto:[email protected]]
<br>
<b>Sent:</b> Monday, September 09, 2013 1:12 PM<br>
<b>To:</b> [email protected]<br>
<b>Subject:</b> [Nagios-users] Splunk Integration Question...<o:p></o:p></s=
pan></p>
<p class=3D"MsoNormal" style=3D"margin-left:.5in"><o:p>&nbsp;</o:p></p>
<div>
<div>
<div>
<div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in">Greetings,<o:p></o:p></p>
</div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:0in;margin-right:0in;mar=
gin-bottom:12.0pt;margin-left:.5in">
&nbsp; I was hoping I might find someone who's got the splunk integration a=
ctively working.&nbsp; I'm running Nagios Core (via EPEL) and Splunk 5.0.3 =
on OracleLinux 6.4.<o:p></o:p></p>
</div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in">&nbsp;&nbsp; When I edit =
cgi.cfg and enable splunk integration, then set the splunk URL to
<a href=3D"https://%3cmysplunkserver%3e:8000/en-US/app/search/flastimeline"=
>https://&lt;mysplunkserver&gt;:8000/en-US/app/search/flastimeline</a>, I n=
otice the nagios URLs look like: https://&lt;mysplunkserver&gt;:8000/en-US/=
app/flashtimeline?q=3Dsearch%<a href=3D"http://20test1.udayton.edu">20test1=
.udayton.edu</a>%20&lt;nagios
 plugin check&gt;.&nbsp; I have two questions...<o:p></o:p></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:1.0in;text-indent:-.25in;mso-list:l0 level1 lfo1">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol"><s=
pan style=3D"mso-list:Ignore">&middot;<span style=3D"font:7.0pt &quot;Times=
 New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Is there a way I can make nagios use the hos=
tname only, not the FQDN?&nbsp; We use short names in splunk so we don't a =
mix of fqdn and short names since we use both forwarders and syslog as inpu=
t.<o:p></o:p></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto;margin-left:1.0in;text-indent:-.25in;mso-list:l0 level1 lfo1">
<![if !supportLists]><span style=3D"font-size:10.0pt;font-family:Symbol"><s=
pan style=3D"mso-list:Ignore">&middot;<span style=3D"font:7.0pt &quot;Times=
 New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>What data is this query looking for, is it e=
xpected that I should have my nagios log in splunk?&nbsp; The &lt;nagios pl=
ugin check&gt; in the query doesn't seem useful to me, unless there's splun=
k data specifically tied to that check, and
 I'm hoping someone could provide an example.<br clear=3D"all">
<o:p></o:p></p>
</div>
<div>
<div>
<div>
<div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in">Kind regards,<o:p></o:p><=
/p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-left:.5in">-- <o:p></o:p></p>
<div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:0in;margin-right:0in;mar=
gin-bottom:12.0pt;margin-left:.5in">
Sean M. Alderman<br>
Senior Engineer, UDit Systems Integration and Engineering<br>
University of Dayton<o:p></o:p></p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</body>
</html>

--_000_3FC36F2C7B96D444A1138066E952D2B60DF744PEPWMC00171corppe_--


--===============3985722776991225315==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

------------------------------------------------------------------------------
How ServiceNow helps IT people transform IT departments:
1. Consolidate legacy IT systems to a single system of record for IT
2. Standardize and globalize service processes across IT
3. Implement zero-touch automation to replace manual, redundant tasks
http://pubads.g.doubleclick.net/gampad/clk?id=51271111&iu=/4140/ostg.clktrk
--===============3985722776991225315==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Nagios-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/nagios-users
::: Please include Nagios version, plugin version (-v) and OS when reporting any issue. 
::: Messages without supporting info will risk being sent to /dev/null
--===============3985722776991225315==--