After posting about the SPLing Bee back in November, I have got around to trying it out myself. After working out a few bugs, shout out to Charlie Huggard for the help, I have the SPLing Bee ready for download.
In the app, there is the dashboards, inputs, indexes, props, and macros configuration files.
connection_host = ip
index = spl_bee
sourcetype = spl_bee_json
source = spl_bee_input
[spl_bee] coldPath = $SPLUNK_DB/spl_bee/colddb homePath = $SPLUNK_DB/spl_bee/db maxTotalDataSizeMB = 512000 thawedPath = $SPLUNK_DB/spl_bee/thaweddb
[spl_bee_results_csv] INDEXED_EXTRACTIONS = csv KV_MODE = none NO_BINARY_CHECK = true SHOULD_LINEMERGE = false TIMESTAMP_FIELDS = LatestSubmissionTime category = Structured description = Comma-separated value format. Set header and other settings in "Delimited Settings" disabled = false pulldown_type = true DATETIME_CONFIG =
[spl_bee_json] KV_MODE=json NO_BINARY_CHECK = true category = Structured disabled = false pulldown_type = true
definition = inputlookup round1.csv | append [| inputlookup round2.csv] | append [| inputlookup round3.csv] | append [| inputlookup round4.csv] | append [| inputlookup round5.csv] | append [| inputlookup round6.csv] | append [| inputlookup round7.csv] | append [| inputlookup round8.csv] | append [| inputlookup round9.csv]
iseval = 0
If the Splunk indexer you are using to play/judge is publicly available, you can have the contestants use Splunk Cloud trial to spin up machines to play. If your indexer is on a private network, you will need to spin up a Splunk indexer/heavy forwarder to be able to play. The contestant will need a full instance of Splunk and not a universal forwarder as they will need to index data, run searches against the data, and add a Splunk application to the indexer.
Things to do when setting up the game.
- Make sure that the indexer isn’t setup to use port 9997. The SPLing Bee app will setup a TCP input to listen to port 9997.
- Update the text Round 1 of the dashboard with the correct instructions for the contest and where to send the data.
- Make sure there are machines available for the contestants or have the main indexer publicly facing so they can use a Splunk Cloud trial.
For running the contest, Splunk wrote the SPLing_Bee_Directions for .conf2015.