Post installation setup
Contents
Post installation setup
After installing Splunk for WebSphere in your environment, on the search head, run the App and run the following saved searches so that associated dashboards populate correctly:
Logs are stored in the default WAS directory structure
If your logs are stored in the default WAS directory structure, then do the following:
In the Views menu, select Saved Searches:
- Run setup_dropdown.
- Run setup_log. Run this search only when you collect log data stored within the WAS default structure.
Logs are stored in the default WAS directory structure and in other locations
If your logs are stored in the default WAS directory structure and in other locations, then do the following:
In the Views menu, select Saved Searches:
- Run setup_dropdown.
- Run cell_node_server_host_path if you store your log data outside the default WAS directory structure.
- ssh onto your search head and create a local directory in
$SPLUNK_HOME/etc/apps/splunk_app_was/if it does not already exist. - Copy
$SPLUNK_HOME/etc/apps/splunk_app_was/default/datato$SPLUNK_HOME/etc/apps/splunk_app_was/local/data. - Rename all
<xyz>_logs_otherpath.xmlto<xyz>.xmlto use thecell_node_server_host_pathlookup file. - Restart Splunk on the search head.
This documentation applies to the following versions of WAS: 2.0.1 View the Article History for its revisions.