Getting Data In

How do I pull a log file directly in as a metric?

daniel333
Builder

All,

I am playing with metricbeat and I am happy camper with it. I was wondering if there was a way to pull the metricbeat logs in directly as a metric rather than as a log?

Example logs
2017-12-17T18:54:16.241-0500 INFO logp/core_test.go:13 unnamed global logger
2017-12-17T18:54:16.242-0500 INFO [example] logp/core_test.go:16 some message
2017-12-17T18:54:16.242-0500 INFO [example] logp/core_test.go:19 some message {"x": 1}

Tags (1)
0 Karma

iamarkaprabha
Contributor

You can try using uberagent app.
https://splunkbase.splunk.com/app/1448/

back2root
Path Finder

Maybe you wanna have a look at Splunk 7.2.0 newest feature "log-to-metrics conversion":
http://docs.splunk.com/Documentation/Splunk/7.2.0/Metrics/L2MOverview

Pre 7.2.0 you need to write props/transforms: http://docs.splunk.com/Documentation/Splunk/7.1.3/Metrics/GetMetricsInOther

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...