Dell PowerStore 1200T Using the Common Event Enabler 8.x on Windows Platforms - Page 49
Managing Indexing, Set up access for Splunk
View all Dell PowerStore 1200T manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 49 highlights
9 Managing Indexing The Index sub-facility of CEPA is a mechanism for delivering bulk events in asynchronous mode to partner applications. The delivery cadence is based on either a time period or a number of events. You can use this Index facility to deliver bulk events to Splunk Enterprise or Splunk Cloud. Topics: • Set up access for Splunk Set up access for Splunk About this task Use the Index facility to deliver events to Splunk Enterprise or Splunk Cloud by performing the following steps. You must add Index entries to the Microsoft Windows Registry. NOTE: Any time you modify the CEE section of the Registry, except for Verbose and Debug, you need to restart the EMC CAVA service. Steps 1. Open a command window on the machine where CEE and the Index application are installed and type regedit. 2. On the Windows Registry Editor window, navigate to: HKEY_LOCAL_MACHINE > SOFTWARE > EMC > CEE > CEPP > Index > Configuration a. Double-click Enabled. Specify 1 to enable Index, or 0 to disable it. b. Double-click Endpoint and specify the host and port, or hosts and ports, of the instances where the Splunk consumer application is installed, in the following format: SplunkHEC@https://: where is the URI, IP address, or FQDN of Splunk Enterprise or Splunk Cloud. For example, SplunkHEC@https://10.1.2.1:8088. When setting multiple entries, you must use a ; (semicolon) to separate the individual entries. For example, SplunkHEC@https://10.3.4.20:8088;SplunkHEC@https://10.3.4.40:8088. c. (Optional) FeedInterval specifies how often, in seconds, information is sent from the Index application to the Splunk consumer application. The default is 60 seconds. The range is from 60 seconds to 600 seconds. Update this value only if necessary. d. (Optional) MaxEventsPerFeed specifies how many events are accumulated before information is sent from the Index application to the Splunk consumer application. The default is 100 events. The range is from 10 events to 10,000 events. Update this value only if necessary. 3. Navigate to HKEY_LOCAL_MACHINE > SOFTWARE > EMC > CEE > CEPP > Index > Configuration > SplunkHEC. a. Add a value for Index, which is a user-defined name for the index being used on Splunk Enterprise or Splunk Cloud. Only one index value is allowed. b. Under SplunkHEC, create a key for the Host server using the URI, FQDN, or IP address of the instance (used as in the EndPoint above) where the Splunk consumer application is installed. c. Under that key, create a REG_SZ value called Token. Copy the token value that is defined in the HTTP Event Collector in Splunk Enterprise or Splunk Cloud to here. NOTE: To use multiple instances of the Splunk consumer application, you must create multiple sub keys under SplunkHEC in the registry - one for each location - and specify a token for each instance. 4. Restart the EMC CAVA service by using the Windows Service Control Manager. Managing Indexing 49