Getting Data In

Is Splunk the right tool for ESXTOP?

dbeez
New Member

Hello All,

I'm outputting VMware esxtop data to a csv and was wondering if splunk was the right tool to index and use the data.

I've got esxtop dumping a csv with 30 minutes of data. The csv has a header row.

Each of the columns represents a metric/stat/counter being gathered.

The "events" in this case are timestamps of resource utilization/performance data.

Is splunk the right tool for this, or should I be looking elsewhere?

Thanks,
db

Tags (2)
0 Karma

lguinn2
Legend

You can do automatic field extraction based on the CSV headers, but it is a bit gawky. Here's the documentation on Extract fields from file headers

I hope this doesn't cause more questions than it answers, but feel free to post the questions here!

0 Karma

dbeez
New Member

Is there a way to do this automatically - there are thousands of columns.

I have a header row in csv format - can't I just tell extraction to follow the header row as far as field classification goes? Each non-header row follows the same regex pattern.

The way I see it now I have to manually create each field.

Apologies on my splunk illiteracy.

0 Karma

bmacias84
Champion

Yes, Splunk can handle the data just fine, just build your extractions.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...