I'm trying to use the "Splunk Add-on for BMC Remedy" add-on under Splunk Enterprise.
I have a Remedy server, SplunkFwdr, with the universal forwarder installed and it identifies my Splunk Enterprise server, SplunkEnt, as the receiving indexer using port 9997.
I installed the add-on to the Splunk server and the universal forwarder on my Remedy server.
I copied the "rpa-inputs-ta" and "rpa-ta" directories from \\SplunkEnt\Program Files\Splunk\etc\apps\platform_advisor_remedy\appserver\addons\ to the \\SplunkFwdr\Program Files\SplunkUniversalForwarder\etc\apps\ tree and modified the log paths in inputs.conf to reflect the log path residing on the SplunkFwdr server (ex: \\SplunkFwdr\Program Files\BMC Software\ARSystem\Arserver\Db\aruser.log).
My confusion is that when I try to configure Forwarded Inputs\TCP, I don't see where to specify the input from the "Splunk Add-on for BMC Remedy" add-on. I tried specifying the directory in which the logs sit in but that did not work.
Does anyone have experience with the "Splunk Add-on for BMC Remedy" add on and how to configure it?
Thank you very much
Regards,
Paul
↧