Getting Data In

How to get counter values in a metrics Index?

New Member

Hi Splunkers,

I am currently working on collecting my SNMP network performance data on Splunk 7.3.3. As SNMP polling tool I use CA Spectrum and its component SSLOGGER.

I prepare the data with some scripts to get the following output:


In Splunk I read the file as usual, assign it to a Metrics Index and use a transforms to set the META fields and dimensions relevant for Metrics Store:

REGEX = ^[^,]+,([^,]+),([^,]*),([^,]+),([^,]+),([^,]+),([^,]+),([^,]+),([^,]+),([^,]+)
FORMAT = ModelName::$2 Instance::$3 metric_name::$4 _value::$5  SwitchType::$6 DeviceClass::$7 SpectrumTopology::$8 BU::$9


This works fine so far, except that Splunk reads the _value as GAUGE (this is default type) and unfortunately I couldn't find a way to tell him that it is a COUNTER value. In the manual I can only find for a solution for StatsD, to handle GAUGE and COUNTER values by |g and |c, but unfortunately I can't find out how to do this with a CSV input.

Can anyone help me?

0 Karma
Get Updates on the Splunk Community!

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...

Admin Your Splunk Cloud, Your Way

Join us to maximize different techniques to best tune Splunk Cloud. In this Tech Enablement, you will get ...

Cloud Platform | Discontinuing support for TLS version 1.0 and 1.1

Overview Transport Layer Security (TLS) is a security communications protocol that lets two computers, ...