Setting Up iDRAC Telemetry with Splunk
Helpful Links
Section titled “Helpful Links”Dell API Docs: https://developer.dell.com/apis/2978/versions/5.xx/docs/0WhatsNew.md
Redfish Telemetry Whitepaper: https://www.dmtf.org/sites/default/files/standards/documents/DSP2051_1.0.0.pdf
Description of the AMQP Messaging Protocol: https://www.ionos.com/digitalguide/websites/web-development/advanced-message-queuing-protocol-amqp/
Setting Up Splunk for the First Time: https://docs.splunk.com/Documentation/Splunk/8.2.4/Installation/StartSplunkforthefirsttime
Integrate iDRAC Telemetry Data Into Splunk: Link to PDF
My Test Environment
Section titled “My Test Environment”NAME="Red Hat Enterprise Linux"VERSION="8.5 (Ootpa)"ID="rhel"ID_LIKE="fedora"VERSION_ID="8.5"PLATFORM_ID="platform:el8"PRETTY_NAME="Red Hat Enterprise Linux 8.5 (Ootpa)"ANSI_COLOR="0;31"CPE_NAME="cpe:/o:redhat:enterprise_linux:8::baseos"HOME_URL="https://www.redhat.com/"DOCUMENTATION_URL="https://access.redhat.com/documentation/red_hat_enterprise_linux/8/"BUG_REPORT_URL="https://bugzilla.redhat.com/"
REDHAT_BUGZILLA_PRODUCT="Red Hat Enterprise Linux 8"REDHAT_BUGZILLA_PRODUCT_VERSION=8.5REDHAT_SUPPORT_PRODUCT="Red Hat Enterprise Linux"REDHAT_SUPPORT_PRODUCT_VERSION="8.5"Red Hat Enterprise Linux release 8.5 (Ootpa)Red Hat Enterprise Linux release 8.5 (Ootpa)Installation
Section titled “Installation”Setup Splunk
Section titled “Setup Splunk”- Download trial of Splunk
- Follow Splunk installation instructions
- By default it will install to /opt/splunk. Run
/opt/splunk/bin/splunk start(I suggest you do this in tmux or another terminal emulator) - Run
firewall-cmd --permanent --zone public --add-port=8000/tcp && firewall-cmd --reload - Make splunk start on boot with
/opt/splunk/bin/splunk enable boot-start
Using Syslog
Section titled “Using Syslog”- Following the instructions here
- Install podman with
dnf install -y podman - Follow the instructions here
1.NOTE: When adding the HTTP input in Splunk it failed out because the token weren’t enabled. I had to manually edit
/opt/splunk/etc/apps/splunk_httpinput/default/inputs.confand set disabled to 0 then do asystemctl restart splunk - Run
systemctl stop rsyslog && systemctl disable rsyslog
Using ActiveMQ and splunkpump
Section titled “Using ActiveMQ and splunkpump”-
dnf install -y podman -
mkdir -p mkdir -p /opt/activemq/data && /opt/activemq/conf -
Run the following to generate default configs:
Terminal window podman run --user root --rm -ti -p 61616:61616 -p 8161:8161 -v /opt/activemq/conf:/mnt/conf:z -v /opt/activemq/data:/mnt/data:z rmohr/activemq /bin/shchown activemq:activemq /mnt/confchown activemq:activemq /mnt/datacp -a /opt/activemq/conf/* /mnt/conf/cp -a /opt/activemq/data/* /mnt/data/exit -
podman run -p 61616:61616 -p 8161:8161 -v /opt/activemq/conf:/opt/activemq/conf -v /opt/activemq/data:/opt/activemq/data rmohr/activemq
Configure the iDRAC
Section titled “Configure the iDRAC”- Download this script which will enable telemetry reports.
- Run
EnableOrDisableAllTelemetryReports.py -ip $target -u $user -p $password1.This enables telemetry on the target server
Using ActiveMQ and splunkpump
Section titled “Using ActiveMQ and splunkpump”Using Syslog
Section titled “Using Syslog”-
Next you will need to enable Redfish alerting which will publish the events to Splunk. Download this script
-
Run the following command
SubscriptionManagementREDFISH.py -ip $target -u $user -p $password -c y -D https://$splunkserver/services/collector/raw -E Alert -V Event1.$targetis the ip address or DNS name of the iDRAC 2.$user/$passwordare the username and password for iDRAC 3.$splunkserveris the IP address or DNS name of your Splunk HTTP event collector instance -
On the command line (racadm) 1.SSH to the iDRAC 2.Run
```racadm set idrac.telemetry.RsyslogServer1 "<splunk_ip/fqdn>"racadm set idrac.telemetry.RsyslogServer1port "514"racadm testrsyslogconnection```