Getting Data In

Use of collectd for machine metrics

brent_weaver
Builder

I just started to tinker with collectd to get metrics into splunk. Alothough easy to get data in, it seems to be VERY verbose. Is there a guide that I can refer to that will being me to a cleaner config? By cleaner I mean more direct information, like cumulitive CPU etc...

Also when writing to HEC I get [ ] around each JSON event making it a bit more manual to parse the events.

Any other thoughts, experiences, other ideas are welcome!

Thanks.

Tags (1)
0 Karma

MuS
Legend

Hi brent_weaver,

try this https://www.splunk.com/pdfs/ebooks/a-beginners-guide-to-collectd.pdf maybe it contains some useful information.

cheers, MuS

0 Karma

brent_weaver
Builder

Thank you for the response and I have seen that. Do you know why there is a leading [ and a trailing ] on every event? It is supposed to be JSON output but it actually isn't valid. I have to:

index=main | rex "[(?P.*)]" | spath input=json

to get this to parse correctly. I am able to easily get logs into Splunk just need to know how to remove the ^[ and the ]$.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...