Dell PowerStore 1200T Using the Common Event Enabler 8.x on Windows Platforms - Page 49

Managing Indexing, Set up access for Splunk

Page 49 highlights

9 Managing Indexing The Index sub-facility of CEPA is a mechanism for delivering bulk events in asynchronous mode to partner applications. The delivery cadence is based on either a time period or a number of events. You can use this Index facility to deliver bulk events to Splunk Enterprise or Splunk Cloud. Topics: • Set up access for Splunk Set up access for Splunk About this task Use the Index facility to deliver events to Splunk Enterprise or Splunk Cloud by performing the following steps. You must add Index entries to the Microsoft Windows Registry. NOTE: Any time you modify the CEE section of the Registry, except for Verbose and Debug, you need to restart the EMC CAVA service. Steps 1. Open a command window on the machine where CEE and the Index application are installed and type regedit. 2. On the Windows Registry Editor window, navigate to: HKEY_LOCAL_MACHINE > SOFTWARE > EMC > CEE > CEPP > Index > Configuration a. Double-click Enabled. Specify 1 to enable Index, or 0 to disable it. b. Double-click Endpoint and specify the host and port, or hosts and ports, of the instances where the Splunk consumer application is installed, in the following format: SplunkHEC@https://: where is the URI, IP address, or FQDN of Splunk Enterprise or Splunk Cloud. For example, SplunkHEC@https://10.1.2.1:8088. When setting multiple entries, you must use a ; (semicolon) to separate the individual entries. For example, SplunkHEC@https://10.3.4.20:8088;SplunkHEC@https://10.3.4.40:8088. c. (Optional) FeedInterval specifies how often, in seconds, information is sent from the Index application to the Splunk consumer application. The default is 60 seconds. The range is from 60 seconds to 600 seconds. Update this value only if necessary. d. (Optional) MaxEventsPerFeed specifies how many events are accumulated before information is sent from the Index application to the Splunk consumer application. The default is 100 events. The range is from 10 events to 10,000 events. Update this value only if necessary. 3. Navigate to HKEY_LOCAL_MACHINE > SOFTWARE > EMC > CEE > CEPP > Index > Configuration > SplunkHEC. a. Add a value for Index, which is a user-defined name for the index being used on Splunk Enterprise or Splunk Cloud. Only one index value is allowed. b. Under SplunkHEC, create a key for the Host server using the URI, FQDN, or IP address of the instance (used as in the EndPoint above) where the Splunk consumer application is installed. c. Under that key, create a REG_SZ value called Token. Copy the token value that is defined in the HTTP Event Collector in Splunk Enterprise or Splunk Cloud to here. NOTE: To use multiple instances of the Splunk consumer application, you must create multiple sub keys under SplunkHEC in the registry - one for each location - and specify a token for each instance. 4. Restart the EMC CAVA service by using the Windows Service Control Manager. Managing Indexing 49

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84

Managing Indexing
The Index sub-facility of CEPA is a mechanism for delivering bulk events in asynchronous mode to partner applications. The
delivery cadence is based on either a time period or a number of events. You can use this Index facility to deliver bulk events to
Splunk Enterprise or Splunk Cloud.
Topics:
Set up access for Splunk
Set up access for Splunk
About this task
Use the Index facility to deliver events to Splunk Enterprise or Splunk Cloud by performing the following steps.
You must add Index entries to the Microsoft Windows Registry.
NOTE:
Any time you modify the CEE section of the Registry, except for Verbose and Debug, you need to restart the EMC
CAVA service.
Steps
1.
Open a command window on the machine where CEE and the Index application are installed and type
regedit
.
2.
On the Windows Registry Editor window, navigate to:
HKEY_LOCAL_MACHINE
>
SOFTWARE
>
EMC
>
CEE
>
CEPP
>
Index
>
Configuration
a.
Double-click
Enabled
. Specify
1
to enable Index, or
0
to disable it.
b.
Double-click
Endpoint
and specify the host and port, or hosts and ports, of the instances where the Splunk consumer
application is installed, in the following format:
SplunkHEC@https://<host>:<port>
where
<host>
is the URI, IP address, or FQDN of Splunk Enterprise or Splunk Cloud. For example,
.
When setting multiple entries, you must use a ; (semicolon) to separate the individual entries. For example,
.
c.
(Optional)
FeedInterval
specifies how often, in seconds, information is sent from the Index application to the Splunk
consumer application. The default is 60 seconds. The range is from 60 seconds to 600 seconds. Update this value only if
necessary.
d.
(Optional)
MaxEventsPerFeed
specifies how many events are accumulated before information is sent from the Index
application to the Splunk consumer application. The default is 100 events. The range is from 10 events to 10,000 events.
Update this value only if necessary.
3.
Navigate to
HKEY_LOCAL_MACHINE
>
SOFTWARE
>
EMC
>
CEE
>
CEPP
>
Index
>
Configuration
>
SplunkHEC
.
a.
Add a value for
Index
, which is a user-defined name for the index being used on Splunk Enterprise or Splunk Cloud. Only
one index value is allowed.
b.
Under
SplunkHEC
, create a key for the
Host server
using the URI, FQDN, or IP address of the instance (used as
<host>
in the EndPoint above) where the Splunk consumer application is installed.
c.
Under that key, create a REG_SZ value called
Token
. Copy the token value that is defined in the HTTP Event Collector
in Splunk Enterprise or Splunk Cloud to here.
NOTE:
To use multiple instances of the Splunk consumer application, you must create multiple sub keys under
SplunkHEC in the registry - one for each location - and specify a token for each instance.
4.
Restart the EMC CAVA service by using the Windows Service Control Manager.
9
Managing Indexing
49