GSA / data.gov

Main repository for the data.gov service
https://data.gov
Other
636 stars 100 forks source link

Integrate Splunk as logdrain #1097

Closed adborden closed 1 year ago

adborden commented 5 years ago

User Story

As a Data.gov operator, I want all platform and application logs to stream to Splunk so that I can easily search across all events of the Data.gov platform without having to maintain our own loggin infrastructure.

Details

BSP has Splunk available

Acceptance Criteria

adborden commented 5 years ago

BSP has said they would be able to provide this but have not been able to deliver. They sent instructions for RHEL, but have yet to respond on if they can provide Ubuntu instructions or a .deb package.

adborden commented 4 years ago

From BSP:

Use Splunk Forwarder v 7.3.4 to be in line with the rest of Splunk. He can get the UF from: https://www.splunk.com/page/previous_releases/universalforwarder.

After installing the UF on the host, he will need to make sure to connect the UF to Splunk Deployment Server by running this command:

/opt/splunkforwarder/bin/splunk set deploy-poll \<splunk-endpoint>

Afterwards, if there are specific host logs that he is wanting to send into Splunk he will need to provide the local paths for those logs and I will push out a config package to his UFs.

Hope this provides some help so there can be some traction.

adborden commented 4 years ago

Moving to New for us to re-triage. Is this something we want to take on now? Worth a spike?

nickumia-reisys commented 1 year ago