Getting Data In

What are recommendations for monitoring static files?

renems
Communicator

Hi all,

I tried searching for this issue, since I'd expect this question should be asked a numerous times already. Unfortunately I couldn't find a decent answer.

I have a bunch of files containing system information. It contains cpu, mem info, as well as architecture data etc. Really nice to have in splunk, to enrich existing queries. What is the best way of treating those in splunk? I'd like to get the same info every day, even though the contents did not change. I'm aware of the CRC SALt option, as well as the source::modtime. Can you help me to find the recommended way of dealing with static files?

Tags (2)
0 Karma

vliggio
Communicator

I believe that a lookup would be more appropriate for this. Look at http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Addfieldsfromexternaldatasources

0 Karma

Ayn
Legend

Splunk's file monitor input isn't designed for re-reading data it has already read on some kind of schedule. My advice would be to create a scripted input that you run with the schedule you want and have the script you're calling output the data from whatever static file(s) you want to index.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...