uberAgent

uberAgent Log Collector Splunk App

uberAgent maintains a very detailed and informative log file that can tell you a lot not only about uberAgent’s health but also about the machine uberAgent is running on. Naturally, the log file is stored locally on the computer uberAgent is running on which makes analysis and troubleshooting a bit difficult in large environments. But luckily it is very easy to solve that problem with Splunk!

uberAgent-Log-Collector-Home-dashboard-372x600

What is it

uberAgent Log Collector is a set of associated Splunk apps that collect the data logged by uberAgent, send it to Splunk for indexing and provide dashboards for easy access.

Installation

uberAgent Log Collector consists of the actual app containing the dashboards, a supporting add-on (SA) that creates the index and a technology add-on (TA) for collecting the data. These three components need to be installed on the following systems:

  • App: search head(s)
  • SA: indexer(s)
  • TA: endpoints where uberAgent is deployed

Configuration

The apps don’t require configuration.

Configurable Log Path

Since uberAgent 7.3, the log path is configurable. If you set a custom log path, you have to modify the TA app: copy the default/inputs.conf to local/inputs.conf and adjust the paths accordingly.

System Requirements

The TA requires Splunk’s Universal Forwarder to be installed on the same machine.

Download

The uberAgent Log Collector apps are available in the Splunk App Directory:

uberAgent Log Collector Splunk App