Getting Data In

Index data from shell script with headers

DataOrg
Builder

I want to index a shell script output thro inputs.conf.

I have configured the script

 

[script://$SPLUNK_HOME/etc/apps/search/bin/swapmem.sh]
disabled = false 
host = *
index = index_perform
interval = 30 
source = Perform
sourcetype = Memory

 

 

the output script is 

 

 	     total        used        free      shared  buff/cache   available
Swap:         32767         919       31848

 

 i want to index the first line as header as auto and map the fields vice versa but the output indexes the both lines .

 

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...