Log to Splunk

SplunkĀ® Enterprise (referred to as Splunk) is a built-in integration that offers data analysis and monitoring. Splunk integrates so that users can log data from CSM directly into Splunk.

Go to the Splunk website and set up an account with Splunk to get a user name and password. Then install Splunk on a workstation prior to starting the CSM integration.

Splunk is an application that captures logging information and makes it searchable and easier to read. CSM connects to a Splunk server, and then sends logging information to Splunk. The logging information is viewed by connecting and launching the Splunk application.

The steps to integrate Splunk with CSM are performed in both the CSM Desktop Client and Cherwell Server Manager.

To configure Splunk in the CSM Desktop Client:

  1. In the CSM client, go to Tools > Options.
  2. On the General Options page, select Configure.
  3. Select the Log to Splunk check box. The Server field displays a Not Configured message.
  4. In the Log Level drop-down list, select an option.
  5. Select Configure to open the Splunk Server Settings window.
  6. Define the following settings:
    • Server URL: Provide the URL of the Splunk Server (example: https://splunkserver:8089).
    • User Name: Provide the user name for the Splunk Server acount.
    • Password: Provide the password of the individual with an account on the Splunk Server.
    • Ignore Certificate Errors: Select this check box to ignore certificate errors that might be generated by Splunk using self-signed certificates to encrypt data. Select this check box only if you trust your connection with the server.
  7. Select OK > OK.
    The Splunk Server Settings window closes so you can view the Cherwell Application Server Logging Options window. Configured shows next to the Configure button.
  8. Select OK.
  9. To configure Splunk in the Cherwell Server Manager:

  10. Select Start > All Programs > Cherwell Service Management > Tools > Server Manager.
  11. Select Logging to open the Cherwell Application Server Logging Options window.
  12. Select Log to Splunk.
  13. In the Log Level drop-down list, select an option. The Server section shows Not Configured next to the Configure button until the configuration is complete.
  14. Select Configure to open the Splunk Server Settings window.
  15. Define the following settings:
    • Server URL: Provide the URL of the Splunk Server (example: https://splunkserver:8089).
    • User Name: Provide the user name for the Splunk Server acount.
    • Password: Provide the password of the individual with an account on the Splunk Server.
    • Ignore Certificate Errors: Select this check box to ignore certificate errors that might be generated by Splunk using self-signed certificates to encrypt data. Select this check box only if you trust your connection with the server.
  16. Select OK > OK.
    The Splunk Server Settings window closes so you can view the Cherwell Application Server Logging Options window. Configured shows next to the Configure button.
  17. Select OK.

Read the following documentation for more information.