Getting Data In

What are recommendations for monitoring static files?

renems
Communicator

Hi all,

I tried searching for this issue, since I'd expect this question should be asked a numerous times already. Unfortunately I couldn't find a decent answer.

I have a bunch of files containing system information. It contains cpu, mem info, as well as architecture data etc. Really nice to have in splunk, to enrich existing queries. What is the best way of treating those in splunk? I'd like to get the same info every day, even though the contents did not change. I'm aware of the CRC SALt option, as well as the source::modtime. Can you help me to find the recommended way of dealing with static files?

Tags (2)
0 Karma

vliggio
Communicator

I believe that a lookup would be more appropriate for this. Look at http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Addfieldsfromexternaldatasources

0 Karma

Ayn
Legend

Splunk's file monitor input isn't designed for re-reading data it has already read on some kind of schedule. My advice would be to create a scripted input that you run with the schedule you want and have the script you're calling output the data from whatever static file(s) you want to index.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...