Note: This release of the Canary Splunk Addon and App can be obtained from the links below.
Any unexpected behaviour or issues can also be reported to our support.
Your Canary Console can integrate with Splunk easily. In this article, we'll walk you through installing the integration.
Follow the steps below to install both the App and the Technology Add-on (TA). As a pre-requisite, you'll need an API key and your Console's hostname.
Please download a copy of the files below:
Optional: If you would like to adjust the default index, click here to jump to the steps required.
Note: Splunk 8.0.0 and higher are required for the new Canary integration.
Step 1: Log in to your Splunk console
Head over to your App Settings menu.
Step 2: Uploading and Installing the Canary Apps
Select the "Install app from file".
Upload the Canary addon archives by selecting the TA-thinkst-canary*.tgz and thinkst-canary-app*.tgz files using the Install App from File menu.
Make sure to repeat the process to upload both files.
Step 3: Configuring the Add-on.
Once uploaded we can head over to the Add-on configuration.
Here we can configure the add-on to fetch data from your Console.
Select the Configuration tab, then the Add button.
A window will now display where you can enter the details of your Canary Console.
Account Name: Enter an identifier for your Console which we will later use to reference the connection.
Console Name: Enter your Console's domain hash.
API Key: Insert your Console's API key.
Note: Your Console's domain hash and API key can be found in your Console's global settings. Further reading on where to locate the details can be found here.
Once complete click the "Add" button.
Step 4: Enabling data inputs.
Head over to the Inputs tab, here we'll enable the inputs and edit each one to make use of the Console connection.
Select each input and edit the Index if necessary then select the account name that we created previously.
Note: Remember to do this for each data input to ensure you are collecting all data.
Once complete enable each input to start collecting data.
Step 5: Viewing Data
Finally, to start browsing data, select the Apps drop-down menu then select the Canary app to view the dashboard.
Note: It may take some time to populate data into the dashboard, and perform the initial sync. If you don't have any data after a couple of hours, contact our support team firstname.lastname@example.org for assistance.
You're done! ;-)
Optional: Adjusting the default index.
Head over to the addon's input page one more.
The index column indicates the current index data will be inserted into.
Select the pencil icon of the input you'd like to modify the index of.
Step 1: Update inputs.
Insert your preferred index then click the Update button when done.
Repeat the change for the other index you'd like adjusted.
Step 2: Updating the Search Macro.
Click on the settings drop-down menu then Advanced search.
Click on Search Macro's
Click on the canarytools_index entry.
Update the Definition entry with your preferred index, then click Save when complete.