Getting Data In

indexing the data

splunkpoornima
Communicator

Hi all,

while adding the input data to the splunk at final stage it has some three options as,

1.)Continuously index data from a file or directory this Splunk instance can access

2.) Upload and index a file

3.)Index a file once from this Splunk server

what is the Use of those options ..

and my requirement is i have one folder which everday my data will be loaded into that folder ..i want the splunk to automatically index the data in to the server and keep updated ..

which option i hav to use for this purpose

Tags (1)
0 Karma

splunkIT
Splunk Employee
Splunk Employee

How is your data being loaded to that folder being mentioned? Do you have a script that copies the log/data files into it, or does the application writes the logs/data directly into it? If the scenario is that your application writes the logs directly into this directory, then probably option 1 would be the choice. What type of log or data is this?

Ayn
Legend

"The" taskmanager logs? I concur with lisa's suggestion. Read the manual.

0 Karma

splunkpoornima
Communicator

I have the Taskmanger Logs ..but still now i do dint use the any script or application for that ..plz clarify me wt kind of application i have to use

0 Karma

lguinn2
Legend

All the Splunk manuals are online at http://docs.splunk.com

I suggest that you start with the manual Getting Data In and look at the monitor option.

Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...