icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Lansweeper Add-on for Splunk
SHA256 checksum (lansweeper-add-on-for-splunk_135.tgz) c14e6a73ca3fb296f538d02c52462cf69f5b7451776213dc1f58fea9ff7f026a SHA256 checksum (lansweeper-add-on-for-splunk_134.tgz) 8c8f6fc835b4dd524440d6654e478a0a35208e8425703b618bd4147c83756af8 SHA256 checksum (lansweeper-add-on-for-splunk_133.tgz) a26e1c1bd7a7a804dd64c5f3109d341d4e22bdd8e115c3c9e81596a82d169878 SHA256 checksum (lansweeper-add-on-for-splunk_132.tgz) da9bfe94290f17544266525f17ef50263fbd4eb8526dd0b83e9b052033fa7023 SHA256 checksum (lansweeper-add-on-for-splunk_131.tgz) f08d8ff5deb2db2225838f5e705542ff7dd17dd1aa4d4a61df2e91c7da997c5d SHA256 checksum (lansweeper-add-on-for-splunk_130.tgz) e0518a69a5fb189bdc7951d243e5b1d492e9dac2155d6dd88911c91f0db3c303 SHA256 checksum (lansweeper-add-on-for-splunk_123.tgz) b803e7f02c468e40dfc5d9c08a31abdbd8ccb164aaca1c797a2cbbc36a6c37ec SHA256 checksum (lansweeper-add-on-for-splunk_122.tgz) 5969fa85a267b79be9e0678c77862c74b3dc008c6428d52558157690681d955e SHA256 checksum (lansweeper-add-on-for-splunk_121.tgz) 13538a262b02bde4469a1b38d302eb343b0b18a14bdf00dbcb3b1580ff0d496d SHA256 checksum (lansweeper-add-on-for-splunk_110.tgz) 021548380b7261648223c5f8c7144f223edd5cc012f052e97e5bb6fcd52140c5 SHA256 checksum (lansweeper-add-on-for-splunk_101.tgz) 4d4e6405955ac5911bf273f0bb437da99a5c3e813c688a8eb3e9c3a7d5df3f81 SHA256 checksum (lansweeper-add-on-for-splunk_100.tgz) 6901da9f804daee1f293ae67eb240023fdc80f7af64b6837e117e217c5950f6f
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

Lansweeper Add-on for Splunk

Splunk Cloud
Overview
Details
The Lansweeper Add-on for Splunk is a Splunk App that allows users to collect information (assets) from Lansweeper (Cloud or On-prem) into Splunk. It consists of python scripts to collect the data alongside configuration pages in UI to configure the data collection.

Use the "Lansweeper App for Splunk" (https://splunkbase.splunk.com/app/5419) to visualize the data on the dashboards.
Use the "Cyences App for Splunk" (https://splunkbase.splunk.com/app/5351/) to better utilize the data for Security, IT, and Auditing.

OVERVIEW

The Lansweeper Add-on for Splunk is a Splunk App that allows users to collect information (assets) from Lansweeper (Cloud or On-prem) into Splunk. It consists of python scripts to collect the data alongside configuration pages in UI to configure the data collection.

Use the Lansweeper App for Splunk to visualize the data on the dashboards.
Use the Cyences App for Splunk to utilize data in a better way for Security, IT and Auditing.

  • Author - CrossRealms International Inc.
  • Creates Index - False
  • Compatible with:
  • OS: Platform Independent
  • Browser: Google Chrome, Mozilla Firefox, Safari

TOPOLOGY AND SETTING UP SPLUNK ENVIRONMENT

This app can be set up in two ways:
1. Standalone Mode:
* Install the Lansweeper Add-on for Splunk.
2. Distributed Mode:
* Install the Lansweeper Add-on for Splunk on the search head. The Add-on configuration is not required on the search head.
* Install the Lansweeper Add-on for Splunk on the heavy forwarder. Configure the Add-on to collect the required information from the Lansweeper on the heavy forwarder.
* The Add-on do not support universal forwarder as it requires python modular inputs to collect the data from Lansweeper.
* The Add-on do not require on the Indexer.

DEPENDENCIES

  • The Add-on does not have any external dependencies if you want to collect data from Lansweeper cloud.
  • If you wish to collect data from on-prem database, you need https://splunkbase.splunk.com/app/2686/">Splunk DB Connect to collect data. See DATA COLLECTION & CONFIGURATION FROM ON-PREM for more information about on-prem data collection.

INSTALLATION

The Lansweeper Add-on needs to be installed on the Search Head and heavy forwarder.

  • From the Splunk Web home screen, click the gear icon next to Apps.
  • Click on Browse more apps.
  • Search for Lansweeper Add-on for Splunk and click Install.
  • Restart Splunk if you are prompted.

DATA COLLECTION & CONFIGURATION FROM CLOUD

Lansweeper API Documentation

Configuration Required on Lansweeper Cloud

Configure Account

  • Navigate to Lansweeper Add-on for Splunk > Configuration > Account on Splunk UI.
  • Click on Add.
  • Add below parameters:
Parameter Description
Account name Any unique name to distinguish this client-id and secret from other in case of multiple accounts configured in the Add-on.
Client Id Client id received from Lansweeper.
Client Secret Client secret received from Lansweeper.
Redirect url This field will be auto-populated. Do not make any changes.
  • Click on Add.
  • If you see time-out issue while saving the account, retry. The time-out is set to 30 seconds.

Configure Data Input

  • Navigate to Lansweeper Add-on for Splunk > Input on Splunk UI.
  • Click on Create New Input.
  • Add below parameters:
Parameter Description
Name An unique name for the Input.
Interval Interval in seconds, at which the Add-on should collect latest data from Lansweeper API. Ideal value is between 3600 (1 hour) to 14400 (4 hour).
Index Select/Type the index name in which lansweeper data will be stored in Splunk. The index name by default supported by Lansweeper App for Splunk is lansweeper.
Account Name Select the account name configured in the Configuration page, which you want to use for data collection.
Site Select the site names from Lansweeper for which you want to collect the data.
  • Click on Save.

DATA COLLECTION & CONFIGURATION FROM ON-PREM

Lansweeper Database Documentation

  • To see Lansweeper database structure and more information refer to Lansweeper on-prem UI.

Configuration Required for Lansweeper Database

  1. To connect Splunk with on-prem Lansweeper database, the Lansweeper database need to be migrated to some that supports remote connection.
  2. Create a new user to Lansweeper database for Splunk to use. Use a separate read-only user for security reasons.
  3. Make sure you have following things about the database handy for Splunk connection:
    • Lansweeper database server IP address
    • Lansweeper database remote connection port (Make sure if the Splunk Heavy forwarder is on remote machine, firewall allows this connection.)
    • Username and Password for the the user that you just created in above step no. 2.
  4. Contact to Lansweeper administrator for above discussion.

Configure Splunk DB Connect for Data Collection

  1. Make sure you install Lansweeper Add-on for Splunk on the server where you are configuring Splunk DB Connect.
  2. Add required driver to Splunk DB Connect App as per the lansweeper Database.
  3. Go to Splunk DB Connect on Splunk Heavy Forwarder.
  4. Go to Configuration on the navigation of the DB Connect App.
  5. Go to identities and create a new identity.
    • Identity Name - Unique name of identity
    • Username - Username for the Lansweeper database
    • Password - Password for the Lansweeper database
  6. Go to Configuration > Connections and create a new connection.
    • Connection Name - Unique name for the database connection
    • Identify - Select the identity created in previous step.
    • Connection Type - Select appropriate database connection type
    • Timezone - Timezone of database server
    • Host - Hostname of IP Address of database server
    • Port - Port number of database connection (Refer to Configuration Required for Lansweeper Database section above.)
    • Default Database - Use lansweeper_db

Configure Data Input

  • To create input use db_inputs.conf.template file from default directory of the App.
  • If you wish to create the input from DB Connect UI, refer the db_inputs.conf.template file for reference.

UNINSTALL APP

To uninstall app, user can follow below steps: * SSH to the Splunk instance. * Go to folder apps($SPLUNK_HOME/etc/apps). * Remove the TA-lansweeper-add-on-for-splunk folder from apps directory. * Remove the DB Connect Identity, Connection and Inputs that you have created. * Restart Splunk.

OPEN SOURCE COMPONENTS AND LICENSES

CONTRIBUTORS

  • Vatsal Jagani
  • Usama Houlila
  • Preston Carter
  • Bhavik Bhalodia
  • Mahir Chavda
  • Hardik Dholariya

SUPPORT

Release Notes

Version 1.3.5
Dec. 12, 2024
  • Splunk-python-sdk updated to the latest version.
Version 1.3.4
March 28, 2024
  • Fixed configuration for timestamp extraction.
  • Made field name changes as per the API changes.
Version 1.3.3
Jan. 16, 2024
  • Updated the API headers.
  • To improve the data collection performance, increased the assets per page limit from 100 to 500.
Version 1.3.2
Oct. 30, 2023
  • Fixed the token expired issue
    • What was the issue?: The access token was not getting renewed because the Lansweeper API now returns 401 status code when token is not valid. Earlier it was returning 400 status code.
    • Account reconfiguration is required only if the data collection does not auto resume after addon upgrade.
Version 1.3.1
Sept. 14, 2022
  • Handled the Lansweeper API issue.
    • What was the issue?: As recently noticed (Sep 2022) Lansweeper API removed the field "_id" from the API response. The Lansweeper API Document still does not mention anything about this change on it.
    • But the Add-on now handles the situation gracefully by using the "key" field in the absence of "_id" field.
  • Updated splunklib to the latest version (v1.7.2) to resolve the App-Inspect Failure.

Note: Data collection by DB connect directly from the on-prem Lansweeper server does not have any impact with the above changes from version 1.3.1.

Version 1.3.0
April 13, 2022
  • Enhancement to fetch Anti-virus details for all the assets
  • UCC Migration to resolve App-inspect failure.
Version 1.2.3
Dec. 10, 2021

Version 1.2.3
Fixed the data collection stopped working (due to token expire) issue. (Root Cause: Change in the API response format.)
Added more debug logs in data-collection input code.

Version 1.2.0
* Changing Lansweeper API from V1 to V2

Version 1.2.2
Nov. 9, 2021

Version 1.2.2
* Cloud compatibility issue (Missing trigger in app.conf) fixed.

Version 1.2.1
* Changing SourceType for API V2 to sourcetype=lansweeper:asset:v2

Version 1.2.0
* Changing Lansweeper API from V1 to V2

Version 1.2.1
June 21, 2021

Version 1.2.1
* Changing SourceType for API V2 to sourcetype=lansweeper:asset:v2

Version 1.2.0
* Changing Lansweeper API from V1 to V2

Version 1.1.0
April 2, 2021
  • On-prem Lansweeper Support added (with database connection by DB Connect).
  • Added more fields for cloud data collection.
Version 1.0.1
Feb. 9, 2021
  • Resolved App-Inspect Failure (nested App present in the package).
Version 1.0.0
Jan. 30, 2021
  • Created Add-on by UCC Splunk-Python library.
  • Added Add-on's Configuration pages.

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk LLC in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.