This TA is deployed on Forwarders, Indexers and Search Heads.
This TA can be deployed to the indexer without any further changes.
It is recommended to create a new index called cacti. An indexes.conf file is not included with this TA.
Install and Deploy the app to the search head.
On the search head, the add-on will provide:
* search time extractions, lookups, macros and event types
To complete the install, you will need to update the follow:
* cacti_index: replace index=cacti with the appropriate index
To complete the ingestion of data, deploy the Splunk_TA_Cacti to the forwarder installed on the same host as your Cacti implementation. If you have multiple installs, you can deploy it across multiple Cacti servers.
For this add-on to work, you will need to have installed the Cacti Mirage plugin to the Cacti servers.
In addition, you will need the following information:
* Path to Cacti install (i.e. /var/www/html/cacti or /usr/share/cacti)
* Path to mirage_poller_output.log (i.e /var/www/html/cacti/log/mirage_poller_output.log)
* Index to send data to (either default or index=cacti, etc)
For deploying the add-on, copy the following files from the default directory to the local directory.
Edit the local/inputs.conf file and make the following changes:
* enable all inputs stanzas: change disabled = true to disabled = false
* modify all stanzas to reflect the appropriate destination index (i.e. index=cacti)
* Set to the correct path to the mirage_poller_output.log file. This file is generated by the Cacti Mirage plugin
* Set to the correct path to the cacti.log file, which is most likely in the log/ folder inside the Cacti install.
* [script://./bin/cacti_lookup_mirage.py /usr/share/cacti]
* Change /usr/share/cacti to the folder where you installed Cacti
The Splunk_TA_Cacti installed on the forwarder requires a linux based Cacti server with the mysql client available
Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 50GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.