Getting Data In

How to index data from a local process

MatMeredith
Path Finder

I'm using a Splunk forwarder to forward data from an application running on the same Linux box as my forwarder.

Obviously I could have my process write out all the data to disk, and have Splunk monitor these files for new data. However, the disk is already heavily loaded on this box, and this doesn't seem terribly efficient.

Is there a better solution?

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Going through files often is the best solution, but there are alternatives. You could have the application write syslog entries ovto the network and have Splunk receive them, or you could let the application enter data into Splunk directly through its REST API. What's best for your case depends on your case.

Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...