icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

Accept License Agreements

Thank You

Downloading OSS Quorum App for Splunk
SHA256 checksum (oss-quorum-app-for-splunk_103.tgz) ab2daf48beaf0e1430286200d1647013a2a9e56668fb4c26349372ed56758355 SHA256 checksum (oss-quorum-app-for-splunk_102.tgz) 1d59c7b42191808879ccb187204d5b317d67b4c4f13e64c42a5b68fe6c465bba SHA256 checksum (oss-quorum-app-for-splunk_101.tgz) 512fc414670369d9bbbee8efd55ba6da91b14a557421397872f880362b61e24d SHA256 checksum (oss-quorum-app-for-splunk_100.tgz) 44cf8f7654d641529d434e1e47ac305a12f40c7f676c658a6a431369f2f751d8
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

OSS Quorum App for Splunk

Splunk Built
Admins: Please read about Splunk Enterprise 8.0 and the Python 2.7 end-of-life changes and impact on apps and upgradeshere.
Overview
Details
The OSS Quorum App for Splunk contains a set of dashboards and analytics to give you full visibility into the system metrics, application data and ledger so that you can maintain security, stability and performance for your Quorum deployment.

You can contact us with questions at blockchain [at] splunk dot com

OSS Quorum App for Splunk

The Splunk App for Quorum contains a set of dashboards and analytics to give you full visibility into the system metrics, application data and ledger so that you can maintain security, stability and performance for your Quorum deployment.

These dashboards are meant to be a starting point for building analytics around your Quorum blockchain no matter where it is deployed.

In order to take full advantage of the dashboards provided there are 3 types of data sources that should be configured. Not all of these data sources are required to use the app, this is just a small taste of what is possible with Splunk and blockchain!

  1. Quorum Blocks, Transactions, and Events - These logs contain transaction information from the ledger itself and provide insight into operations and actions on-chain. We’ve open sourced Splunk Connect for Ethereum to help you easily ingest Quorum ledgers in Splunk.
  2. Quorum node logs and metrics - These are logs and metrics specific to a Quorum node. Specifically, Quorum application logs, Geth metrics, RPC data polled from different Quorum node endpoints (i.e. admin_peers, txpool_content, etc -- see Splunk Connect for Ethereum for more information).
  3. Infrastructure/System Level Metrics and Logs - System metrics such as CPU,MEM,DISK and NETWORK activity provide insight into the underlying infrastructure Quorum nodes are running on. These metrics/logs could come from physical machines, Docker, Kubernetes, IBM IKS, Microsoft Azure, Google’s GCP and AWS Cloudwatch to name a few. Splunk has different Add-ons and connectors for each.

App Features

Dashboards

There are a few dashboards provided to get you started with analyzing your Quorum deployment. These include:
* Data Setup - A dashboard to show you what data is being received by Splunk.
* Raw Data Flow - A dashboard showing the data flowing in from each Quorum node and data source.
* Infrastructure Health and Monitoring - An overview of system health from system metrics like CPU, uptime status as well as transaction latency. You can see in real time when transactions are starting to back up or a node is falling behind on blocks.
* Transaction Analytics - Real time visibility into the transactions being written on the ledger. See a breakdown of private vs public transactions and analytics around addresses.
* Ledger Query - Query the ledger using specific attributes to get detailed event data.

Getting Started

  • Automated Demo

    1. The easiest way to test and demo the app is using the docker-compose Quorum example included with Splunk Connect for Ethereum.
  • Manual Setup

    1. Install the App on a Splunk Enterprise Search Head that will have access to the data.
    2. Open the App and navigate to the “Data Setup” dashboard from the Introduction Page.
    3. Follow the instructions for each of the 3 data sources on the “Data Setup” page in order to populate the graphs and validate data is coming in correctly.
    • Quorum Block and Transcation Data - Splunk Connect for Ethereum is an open source agent that connects to each node on the Quorum network. See its README for deployment instructions. Docker, Kubernetes, and native deployments are all options.

    • Quorum node logs and metrics - You will need to create event and metric indexes in Splunk as well as an input mechanism to receive the data. We usually like to create an index called “ethereum” and “metrics” and enable the Splunk HEC to receive data. You can use the example “indexes.conf.example” provided in the app. Simply rename the file from “indexes.conf.example” to “indexes.conf” to enable the indexes, and rename “inputs.conf.example” to “inputs.conf” to enable the HEC endpoints. You will also need to enable the HTTP Event Collector (HEC) to receive data if it has not been "enabled" already.
      $ cd $SPLUNK_HOME/etc/apps/splunk-app-quorum/default $ sudo mv inputs.conf.example inputs.conf $ sudo mv indexes.conf.example indexes.conf $ cd /opt/splunk/bin $ sudo ./splunk restart

    • Quorum node JSON-RPC data - Quorum nodes also have RPC endpoints that Splunk Connect for Ethereum can poll and send to Splunk. This can be used to monitor transaction pool activity on a node, active peers, or leader election in Raft or Istanbul. In order for this to work, the required endpoints need to be whitelisted on the Quorum node. See the README at Splunk Connect for Ethereum for more information.

  • System Logs/Metrics - Depending on how you’ve deployed your Quorum network, there is probably a great option to get your System Logs and Metrics for end-to-end visibility. On the data setup dashboard, we’ve provided a list of common options that you can use to get your data into Splunk.

Below is a list of possible environments:
- Docker: Splunk Docker Logging Driver
- Kubernetes: Splunk Connect for Kubernetes
- Syslog: Monitoring Network Ports in Splunk
- Log File: Monitoring Files and Directories with Splunk
- IBM Cloud Platform: IBM Cloud Platform
- Microsoft Azure: Splunk Add-on for Microsoft Cloud Services
- AWS Cloudwatch: Splunk App for AWS
- GCP Stackdriver: Splunk Add-on for Google Cloud

You are now ready to use the OSS Quorum App for Splunk!

Release Notes

Version 1.0.3
Feb. 12, 2020

Version 1.0.2
Feb. 12, 2020

1.0.2
- Updated app logo and README

Version 1.0.1
Feb. 12, 2020

Initial Release

Version 1.0.0
Feb. 12, 2020

Initial Release 1.0.0

15
Installs
114
Downloads
Share Subscribe LOGIN TO DOWNLOAD

Subscribe Share

AppInspect Tooling

Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
© 2005-2020 Splunk Inc. All rights reserved.
Splunk®, Splunk>®, Listen to Your Data®, The Engine for Machine Data®, Hunk®, Splunk Cloud™, Splunk Light™, SPL™ and Splunk MINT™ are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners.