Splunk Dev

How to collect data to index in batches

santosh121
Explorer

Dear All,

 

 I am trying to push some records in patches to splunk i want it to be automated.

 

Usecase: 

 

 We have 1 lakh + records in index and we want to push those 1 lakh+ records in batches  of 500 as we will run some logic on them. How can i collect all these records in loop in splunk.

can i collect in "for loop" or only way is via python or node sdk?

 

Regards,

Santosh

0 Karma

aasabatini
Motivator

Hi @santosh121 

you can use also sh batch in splunk, with the scripted inputs you can schedule when the events are loaded (CRON), anyway it's better read the documentation.

https://docs.splunk.com/Documentation/Splunk/latest/AdvancedDev/ScriptSetup

 

 

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
0 Karma
Get Updates on the Splunk Community!

Demo Day: Strengthen Your SOC with Splunk Enterprise Security 8.1

Today’s threat landscape is more complex than ever. Security operation centers (SOCs) are overwhelmed with ...

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...