Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Config Quest
SHA256 checksum (config-quest_202.tgz) 7d00c8b2b55fb1ab731ce0400d90075010806c108ea48981e969d057c3e52c07 SHA256 checksum (config-quest_101.tgz) 0989a6f5e20168c6f9c96556c0d8de22241e5f27bc1a5dc4d07b54b0c5bfc0ee SHA256 checksum (config-quest_100.tgz) db6f5569b23563587debe4abf3e7bb72b2275659db4b9a233e1b5e796aee78c5
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

Config Quest

Splunk AppInspect Passed
Overview
Details
Config Quest is an awesome lightweight utility from Discovered Intelligence for searching and reviewing Splunk configurations on any Splunk server directly from your search head! Use Config Quest to search for any stanza or configuration parameter, in any selected app, across any Splunk server in your environment.

At the heart of the app are several a powerful dashboards that enable the searching of Splunk configurations by conf file, host, app, stanza and/or parameter. Configurations returned are nicely formatted into the familiar stanza, parameter and value Splunk conf file format, along with text based highlighting to aid visualization and readability. There are dashboards for reviewing configuration changes, finding configuration differences, comparing configurations between hosts and identifying installed application differences.

Simply install on a Search Head and you are good to go. There are no scripts to run or deploy across your environment.

Config Quest by Discovered Intelligence

For support, please email support@discoveredintelligence.ca

What's New In This Release?

  • Many small code tweaks and enhancements
  • New 'Difference Config Quest' dashboard to identify configuration differences across your deployment
  • New 'Comparison Config Quest' dashboard to compare one host's configurations with another
  • New 'Application Config Quest' dashboard to query the installed apps across your deployment and find differences
  • The ability to exclude apps, stanzas and configuration parameters from all dashboards to reduce noise when performing analysis
  • Changes to how the configurations are displayed to allow for copy/pasting into conf files
  • The addition of quick links to useful configuration documentation

Overview

Config Quest is an awesome lightweight utility from Discovered Intelligence for searching and reviewing Splunk configurations on any Splunk server directly from your search head! Use Config Quest to search for any stanza or configuration parameter, in any selected app, across any Splunk server in your environment.

At the heart of the app are several a powerful dashboards that enable the searching of Splunk configurations by conf file, host, app, stanza and/or parameter. Configurations returned are nicely formatted into the familiar stanza, parameter and value Splunk conf file format, along with text based highlighting to aid visualization and readability. There are dashboards for reviewing configuration changes, finding configuration differences, comparing configurations between hosts and identifying installed application differences.

Why is this app useful?

You can use Config Quest to:
- Instantly search for Splunk configurations across any Splunk server in your environment from one place
- Search for configurations by host, wildcard host, conf file, app, stanza and/or parameter
- Identify configuration differences across all your similar Splunk servers (e.g. all indexers)
- Compare configurations on one host with those of another
- Identify all installed applications and application installation differences across your Splunk deployment
- Centrally review your serverclass.conf and view the serverclasses and apps, along with the deployment clients that have been assigned the serverclasses

Why not just use btool?

Config Quest does not replace btool, but instead provides a convenient mechanism to remotely review configurations residing on your Splunk servers, without the need to log into the host and run btool or check files manually. There are no scripts to run, no complex logic to learn and nothing to install other than this app on your Search Head. While btool rolls up configurations using Splunk's inheritance based rules, the configs returned by Config Quest are in their raw state prior to rollup, although some defaults are picked up in the results.

How Does It work?

The app leverages Splunk's REST based commands, then uses complex formatting and logic to present the data in a familiar Splunk Conf file format by stanza, parameter and value.

Are there dashboards/reports?

Yes, there are now five dashboards as follows:
- Current Config Quest - allows for centralized searching and reviewing configurations across all your Splunk servers.
- Difference Config Quest - helps you to find differences in specific configurations across your similar Splunk servers.
- Comparison Config Quest - allows you to compare the configuration on one host with that of another host for a specific Splunk conf file.
- Application Config Quest - helps you to identify application installation differences across your Splunk servers
- Serverclass Config Quest - allows for remote interogation of your Serverclass.conf, presenting a similar view to the deployment server and lists all serverclasses, apps and the deployment clients associated with the various serverclasses

Important Stuff

Requirements:
- Only tested to work on Splunk 6.5 and above
- Splunk servers that you want to view configurations from must be added as search peers to the search head that the app is install on
- If you are looking for the configs in system/local or default - choose the 'system' app from the Current Config Quest dashboard

How do I install this?

The app is super simple to install.
1. Download the app from Splunkbase
2. Install the app on a search head or search head cluster.
3. Restart Splunk - this is because we have a small amount of JS that helps to colour format configurations
4. Go to the app and start your config quest!

For support, to request feature enhancements or simply to give us your feedback - please contact us at support@discoveredintelligence.ca

Future Release

The following items are planned for a future release. Let us know if you would like us to add something!
- Historic conf file analysis - the ability to archive configurations and then reference old configurations and compare against current configurations

Q&A

Any useful support questions and answers will be posted here for others to view

Q. The Difference Config Quest seems to take a long time to run
A. If your environment is large, then broad, unfiltered configuration searches may take a small amount of time to run depending on the configuration file selected and number of hosts you have, but it will complete if you are patient.

Q. I am seeing both local and default configurations being returned
A. Correct, default configurations will be returned when there is no local or app specific configuration taking precedence. There is currently no way to identify whether the configuration presented is in local or default - this is mostly due to the REST API not returning this data.

Release Notes

Version 2.0.2
Sept. 20, 2018

## What's New In This Release? ############################
- Many small code tweaks and enhancements
- New 'Difference Config Quest' dashboard to identify configuration differences across your deployment
- New 'Comparison Config Quest' dashboard to compare one host's configurations with another
- New 'Application Config Quest' dashboard to query the installed apps across your deployment and find differences
- The ability to exclude apps, stanzas and configuration parameters from all dashboards to reduce noise when performing analysis
- Changes to how the configurations are displayed to allow for copy/pasting into conf files
- The addition of quick links to useful configuration documentation

Version 1.0.1
Sept. 21, 2017

Version 1.0.1 - fix to ensure more efficient and accurate population of hosts drop down

Version 1.0.0
Sept. 6, 2017

196
Installs
758
Downloads
Share Subscribe LOGIN TO DOWNLOAD

Subscribe Share

AppInspect Tooling

Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 50GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
© 2005-2018 Splunk Inc. All rights reserved.
Splunk®, Splunk>®, Listen to Your Data®, The Engine for Machine Data®, Hunk®, Splunk Cloud™, Splunk Light™, SPL™ and Splunk MINT™ are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners.