Getting Data In

Use of collectd for machine metrics

brent_weaver
Builder

I just started to tinker with collectd to get metrics into splunk. Alothough easy to get data in, it seems to be VERY verbose. Is there a guide that I can refer to that will being me to a cleaner config? By cleaner I mean more direct information, like cumulitive CPU etc...

Also when writing to HEC I get [ ] around each JSON event making it a bit more manual to parse the events.

Any other thoughts, experiences, other ideas are welcome!

Thanks.

Tags (1)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi brent_weaver,

try this https://www.splunk.com/pdfs/ebooks/a-beginners-guide-to-collectd.pdf maybe it contains some useful information.

cheers, MuS

0 Karma

brent_weaver
Builder

Thank you for the response and I have seen that. Do you know why there is a leading [ and a trailing ] on every event? It is supposed to be JSON output but it actually isn't valid. I have to:

index=main | rex "[(?P.*)]" | spath input=json

to get this to parse correctly. I am able to easily get logs into Splunk just need to know how to remove the ^[ and the ]$.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...