Solved

Commvault role for Splunk app?

  • 23 November 2021
  • 10 replies
  • 301 views

Userlevel 1
Badge +3

Hello,

 

I installed and configured the Commvault Splunk plugin available at: https://splunkbase.splunk.com/app/5718/

 

To respect the “least privilege” rule, I created a service account with the role “Report Management” on the Commcell to allow Splunk to retrieve the logs and jobs information.

 

But it doesn’t work, here are the Splunk logs generated from the plugin:

“2021-11-23 10:03:05.040906 click_result Attempting to login
2021-11-23 10:03:05.598242 click_result ERROR 106 'NoneType' object is not subscriptable”

 

First, I thought it was a password issue but when inserting a false password, I have another log:

“2021-11-23 10:23:08.698105 click_result Password not entered. Please give a password
2021-11-23 10:23:23.800388 click_result Attempting to login
2021-11-23 10:23:23.880586 click_result ERROR Login Failed”

 

I think I don’t gave enough rights to the Splunk service account to access the required information on the Commcell but I don’t want to give the “master” role to this account.

 

I’ve tried to find in documentation.commvault.com what is required but the only available information is about the Splunk backup agent: https://documentation.commvault.com/commvault/v11_sp20/article?p=111273.htm

 

Can you please tell me which are the rights required by the Splunk plugin to access Commvault logs and jobs information?

 

Thank you in advance.

icon

Best answer by Mike Struening RETIRED 1 December 2021, 17:43

View original

10 replies

Userlevel 7
Badge +15

Hi @JohnADP 

There’s two separate concepts here, so I need to understand your objectives.

The splunkbase plugin you refer to is a plugin for splunk to monitor the Commcell.

Whereas the documentation link you provide describes the configuration for a Commvault backup agent to protect a splunk instance.

Are you looking to monitor Commvault with splunk or protect a splunk instance with Commvault?

Thanks,

Stuart

Userlevel 7
Badge +23

Hey @JohnADP,

Just looked at a previous escalation that recently occurred, it seems like there is an updated app from our side that we can provide which may not be on the splunk site yet. Working to confirm this and will get back to you ...

Userlevel 1
Badge +3

Hello Stuart,

I’m sorry, I am looking to monitor Commvault with Splunk.

 

Hello Damian,

Thank you.

 

Regards,

Userlevel 7
Badge +23

@JohnADP , I believe this is what you need:

https://documentation.commvault.com/11.25/essential/144730_splunk_plugin.html

Let me know if that is what you are looking for.

Userlevel 1
Badge +3

Hello,

It was not was I am looking for.

 

In the “Configurations” chapter, the second element is mentionning a CommCell user name and password.

“Enter the CommCell user name and password, and then click Add CommCell.”

 

I need to know what are the rights needed for this account to use the Splunk plugin.

And the documentation page does not mention it.

 

Regards,

Userlevel 7
Badge +23

Thanks, @JohnADP !  I’ll get a doc MR created in your name and get the answer for you posted here as well.

I’ll be in touch.

Userlevel 7
Badge +23

@JohnADP , here you are.  I’ll get an Doc MR created in your name to get this all updated.

Let me know if you have any questions!

 

Userlevel 1
Badge +3

Hello Mike,

 

Thank you for your help.

I will test this role into production and get back to you.

 

Regards,

Userlevel 7
Badge +23

Appreciate that!  Keep me posted.

Userlevel 7
Badge +23

Hey @JohnADP , hope all is well!  Following up to see how this was looking.  Any chance you tested it out?

Thanks!

Reply