Getting Data In

Has anybody tried to index NMON files?

JYTTEJ
Communicator

Hi, I have indexed an NMON file on SPLUNK - just for test purpose as we would like to keep all measurements in one place.

It did not quite work the way I had hoped, as the data records were logged like this without a header:

5:59:47.050 AM

DISKBUSY,T2880,11.6,0.0,0.0,0.0,0.0,0.1,11.6,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0,0.0

2 questions:

1) Can I set up SPLUNK to index the file in another way (with headers)

2) Can I use this record in any way?

Tags (1)
0 Karma

guilmxm
Influencer

Hi, I you are still looking for a solution for NMON within Splunk, take a look at NMON for Splunk App i've just released:

https://apps.splunk.com/app/1753

Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...