<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Use of collectd for machine metrics in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Use-of-collectd-for-machine-metrics/m-p/325690#M93241</link>
    <description>&lt;P&gt;Hi brent_weaver,&lt;/P&gt;

&lt;P&gt;try this &lt;A href="https://www.splunk.com/pdfs/ebooks/a-beginners-guide-to-collectd.pdf"&gt;https://www.splunk.com/pdfs/ebooks/a-beginners-guide-to-collectd.pdf&lt;/A&gt; maybe it contains some useful information.&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
    <pubDate>Thu, 01 Mar 2018 00:30:43 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2018-03-01T00:30:43Z</dc:date>
    <item>
      <title>Use of collectd for machine metrics</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Use-of-collectd-for-machine-metrics/m-p/325689#M93240</link>
      <description>&lt;P&gt;I just started to tinker with collectd to get metrics into splunk. Alothough easy to get data in, it seems to be VERY verbose. Is there a guide that I can refer to that will being me to a cleaner config? By cleaner I mean more direct information, like cumulitive CPU etc...&lt;/P&gt;

&lt;P&gt;Also when writing to HEC I get [ ] around each JSON event making it a bit more manual to parse the events. &lt;/P&gt;

&lt;P&gt;Any other thoughts, experiences, other ideas are welcome!&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Mar 2018 00:21:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Use-of-collectd-for-machine-metrics/m-p/325689#M93240</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2018-03-01T00:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: Use of collectd for machine metrics</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Use-of-collectd-for-machine-metrics/m-p/325690#M93241</link>
      <description>&lt;P&gt;Hi brent_weaver,&lt;/P&gt;

&lt;P&gt;try this &lt;A href="https://www.splunk.com/pdfs/ebooks/a-beginners-guide-to-collectd.pdf"&gt;https://www.splunk.com/pdfs/ebooks/a-beginners-guide-to-collectd.pdf&lt;/A&gt; maybe it contains some useful information.&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Thu, 01 Mar 2018 00:30:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Use-of-collectd-for-machine-metrics/m-p/325690#M93241</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2018-03-01T00:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: Use of collectd for machine metrics</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Use-of-collectd-for-machine-metrics/m-p/325691#M93242</link>
      <description>&lt;P&gt;Thank you for the response and I have seen that. Do you know why there is a leading [ and a trailing ] on every event? It is supposed to be JSON output but it actually isn't valid. I have to:&lt;/P&gt;

&lt;P&gt;index=main | rex "[(?P.*)]" | spath input=json&lt;/P&gt;

&lt;P&gt;to get this to parse correctly. I am able to easily get logs into Splunk just need to know how to remove the ^[ and the ]$.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Mar 2018 02:55:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Use-of-collectd-for-machine-metrics/m-p/325691#M93242</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2018-03-01T02:55:31Z</dc:date>
    </item>
  </channel>
</rss>

