• Twitter
  • LinkedIn
  • Rss
  • Mail
Contact Us: +1 877 605 0747
Discovered Intelligence
  • Company
    • About Us
    • Our Team
    • Careers
    • Life at DI
    • Partners
  • Use Cases
  • Security
    • Splunk
      • Splunk Professional Services
        • Operational Excellence
        • Splunk Cloud Migration
        • Splunk Health Assessments
        • Splunk App Development
      • Aura Asset Intelligence
        • Cyber Asset ASM for Splunk
    • Cribl
      • Cribl Professional Services
        • Cribl Adoption Program
        • Cribl Operational Excellence Program
    • Customer Success
      • Spam Detection Using Machine Learning
      • SMS Spam Compliance
      • SIEM Migration
      • Increased Enterprise Security Visibility
  • Observability
    • Splunk
      • Splunk Professional Services
        • Splunk Operational Excellence Program
        • Splunk Cloud Migration
        • Splunk Health Assessments
        • Splunk Application Development
    • Cribl
      • Cribl Professional Services
        • Cribl Adoption Program
        • Cribl Operational Excellence Program
    • Customer Success
      • Maximizing Data Value Using Cribl
      • Executive Dashboard Optimization
      • Improved Monitoring During Covid
      • Zero Downtime During Tax Season
      • Superior Competitive Intelligence
      • Strategic Advisory Leading to Huge Growth
      • Migrating Splunk from AWS to GCP
  • Solutions
  • Contact
  • Blog
  • Menu Menu
Blog - Latest News
You are here: Home1 / Solutions2 / Apps3 / Introducing Config Quest for Splunk!
Current Quest Dashboard

Introducing Config Quest for Splunk!

September 25, 2017/in Apps, Splunk/by Derek

We are pleased to announce the release of our latest Splunk certified app, Config Quest for Splunk.

Config Quest is an awesome lightweight utility from Discovered Intelligence for searching and reviewing Splunk configurations on any Splunk server directly from your search head! Use Config Quest to search for any stanza or configuration parameter, in any selected app, across any Splunk server in your environment.

At the heart of the app is a powerful dashboard; enabling searching of Splunk configurations by conf file, host, app, stanza and/or parameter. The configurations returned are nicely formatted into the familiar stanza, parameter and value Splunk conf file format, along with text based highlighting to aid visualization and readability.

Simply install on a Search Head and you are good to go. There are no scripts to run or deploy across your environment.

Why is this app useful?

You can use Config Quest to:

  • Instantly search for Splunk configurations across any Splunk server in your environment from one place
  • Search for configurations by host, wildcard host, conf file, app, stanza and/or parameter
  • Centrally review your serverclass.conf and view the serverclasses and apps, along with the deployment clients that have been assigned the serverclasses

The app leverages Splunk’s REST based commands, then uses complex formatting and logic to present the data in a familiar Splunk Conf file format by stanza, parameter and value.

Why not just use btool?

Config Quest does not replace btool, but instead provides a convenient mechanism to remotely review configurations residing on your Splunk servers, without the need to log into the host and run btool or check files manually. There are no scripts to run, no complex logic to learn and nothing to install other than this app on your Search Head. While btool rolls up configurations using Splunk’s inheritance based rules, the configs returned by Config Quest are in their raw state prior to rollup, although some defaults are picked up in the results.

Are there dashboards/reports?

Yes, there are currently two dashboards:

  • Current Config Quest – allows for centralized searching and reviewing configurations across all your Splunk servers

Current Quest Dashboard

  • Serverclass Config Quest – allows for remote interrogation of your Serverclass.conf, presenting a similar view to the deployment server and lists all serverclasses, apps and the deployment clients associated with the various serverclasses

Server Class Quest Dashboard

Future Releases

We are continuously improving our Splunk apps and the following items are planned for a future release. Let us know if you would like us to add something!

  • Historic conf file analysis – the ability to archive configurations and then reference old configurations and compare against current configurations
  • Host or conf files comparison – ability to compare the configs on one host against another host and easily identify differences

For support, to request feature enhancements or simply to give us your feedback – please contact us at support@discoveredintelligence.ca

Looking to expedite your success with Splunk? Click here to view our Splunk service offerings.

© Discovered Intelligence Inc., 2017. Unauthorised use and/or duplication of this material without express and written permission from this site’s owner is strictly prohibited. Excerpts and links may be used, provided that full and clear credit is given to Discovered Intelligence, with appropriate and specific direction (i.e. a linked URL) to this original content.

Tags: app, big data, config, configuration, development, meta, metadata, splunk
Share this entry
  • Share on Facebook
  • Share on Twitter
  • Share on WhatsApp
  • Share on Pinterest
  • Share on LinkedIn
  • Share on Tumblr
  • Share on Vk
  • Share on Reddit
  • Share by Mail
https://discoveredintelligence.com/wp-content/uploads/2017/09/CQ_img1.png 925 1506 Derek https://discoveredintelligence.com/wp-content/uploads/2013/12/DI-Logo1-300x137.png Derek2017-09-25 19:09:392022-10-31 15:52:40Introducing Config Quest for Splunk!
You might also like
Splunk Enterprise 7.2 New Features
Splunk and the Internet of Things (IoT)
Diving into Splunk Table Datasets
Splunk Data Integration – Getting Data Out of Splunk
Harnessing Ingest-Time Eval Fields
Sendresults Command for Splunk
Real World IoT Use Cases
Meta Woot! 2.0 for Splunk Released

SEARCH

From our Blog

  • Building a Unified View: Integrating Google Cloud Platform Events with Splunk
  • Discover the Power of SendResults: A Life-Changing Splunk Command and Alert Action
  • ChatGPT and SPL: A Dynamic Duo for Learning Splunk’s Query Language
  • Wiring up the Splunk OpenTelemetry Collector for Kubernetes
  • What to Consider When Creating Splunk Workload Management Rule Conditions

SUBSCRIBE

Subscribe to our Blog

CONTACT US

    Name*

    Email*

    Company*

    Message

    Answer calculation (enter number)

    © Copyright 2023. Discovered Intelligence Inc.

    From Our Blog

    • Building a Unified View: Integrating Google Cloud Platform Events with Splunk
    • Discover the Power of SendResults: A Life-Changing Splunk Command and Alert Action
    • ChatGPT and SPL: A Dynamic Duo for Learning Splunk’s Query Language
    • Wiring up the Splunk OpenTelemetry Collector for Kubernetes
    Discovered Intelligence Featured in Splunk’s Partner+ Press ReleaseDiscovered Intelligence Recognized as a 2017 Splunk Revolution Award Winner
    Scroll to top