This app integrates Puppet Enterprise or Puppet open source with Splunk to:
* Send Puppet node inventory, node facts, report summaries and report details into Splunk from one or more Puppet primary servers.
* Automate taking action by triggering Bolt tasks from Actionable Alerts (Puppet Enterprise only, requires the Puppet Alert Actions add-on for Splunk).
* Maintain an audit log of Bolt actions that were run.
* Trend Puppet inventory and fact data over time.
* Power example dashboards and searches on Puppet data.
* Provide operational metrics and dashboards for your Puppet deployment.
Use cases:
* Share Puppet's rich, detailed inventory and change data with other teams for searches, dashboards and alerts.
* Trend data over time to track progress or detect issues.
* Make decisions faster by automatically triggering gathering the information you need to make a decision after Splunk has recognized an issue (Puppet Enterprise only).
* Resolve issues faster by automatically triggering remediations after Splunk has recognized an issue (Puppet Enterprise only).
* Monitor the health of your Puppet deployment.
* Log and audit what ad hoc actions were run.
* If you also need to deploy, configure and manage Splunk forwarders there is a Puppet module for that available here (https://forge.puppet.com/puppet/splunk).
Included are:
* Source types for Puppet summary reports, detailed reports, facts, PE orchestrator and activity events, as well as Puppet Bolt runs.
* Actionable Alert to generate Puppet Detailed Reports on demand.
* Example dashboards to see analysis options of the content provided in a report.
This app requires installing the Splunk HEC Report Processor (https://forge.puppet.com/puppetlabs/splunk_hec) on the Puppet Servers one wishes to collect data from.
Resources
Log in to report this app listing