Configure Logging to a Splunk Server

Use the Server Manager to configure event logging to a Splunk Server. (Event logging records significant events and errors, and is used for troubleshooting.) Splunk is a third-party tool that identifies data patterns, provides metrics, diagnoses problems, and provides intelligence for business operations. CSM integrates with Splunk so that CSM event log data can be indexed and made easily searchable. Download and install Splunk onto a server and configure it for logging events.

To configure logging to a Splunk server:

  1. Click Start>All Programs>Cherwell Service Management>Tools>Server Manager.
  2. In the Server drop-down, select a Server or web application.
  3. Click the Logging button.

    The Logging Options window for the selected Server opens.

  4. Select the Log to Splunk check box.
  5. Select the log level from the drop-down:
    • Debug and above: Very verbose messages. Leaving this on continuously can get space and resource intensive.
    • Info and above: Informational messages that can be used to diagnose a problem with your Server.
    • Stats and above: Detailed messages that track performance.
    • Warning and above: Warning messages that occurred while the Server was running.
    • Error and above: Errors that were encountered while the Server was running.
    • Fatal only: Errors that were encountered while the Server was running that caused the Server to stop.
  6. Click the Configure button.
  7. Define the following settings:
    • Server URL: Provide the URL of the Splunk Server (example: https://splunkserver:8089).
    • User Name: Provide the user name for the Splunk Server acount.
    • Password: Provide the password of the individual with an account on the Splunk Server.
    • Ignore Certificate Errors: Select this check box to ignore certificate errors that might be generated by Splunk using self-signed certificates to encrypt data. Select this check box only if you trust your connection with the server.
  8. Click Test to test the CSM Connection to the Splunk Server.
  9. Click OK.

© Copyright 2018 Cherwell Software, LLC. All rights reserved.