Here are some specific queries/problem statement I have :
Yes. This is the most common way of feeding data into Splunk. Manually adding data is (I believe) less common. Filesystem-based inputs will continually monitor files or directories for new data and index it as soon as it arrives. Network-based inputs will do the same for network sockets.
Yes. Have a look at Splunk DB Connect.
Yes. JSON is one, CSV another, and there are more formats available, too. See information in the REST API docs:
Yes. This is the most common way of feeding data into Splunk. Manually adding data is (I believe) less common. Filesystem-based inputs will continually monitor files or directories for new data and index it as soon as it arrives. Network-based inputs will do the same for network sockets.
Yes. Have a look at Splunk DB Connect.
Yes. JSON is one, CSV another, and there are more formats available, too. See information in the REST API docs:
No, that covers more than what I'd like to put in a simple answer. My suggestion is that you read the docs and become familiar with how Splunk works in a distributed environment.
Can you explain in detail how to feed xml data coming over a network and feeding it into splunk?