Getting Data In

Which is best practice, enable the metrics inputs in UF local or windows/nix add on local?

DeputyDawg
Engager

We want to use ITSI with universal forwarders (windows and nix).  Which is best practice, enable the metrics inputs in UF local or windows/nix add on local? 

Labels (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Enable the inputs in an app.  Inputs in etc/system/local cannot be changed by the Deployment Server (DS).  Using a DS is another best practice.

---
If this reply helps you, Karma would be appreciated.

DeputyDawg
Engager

Thank you, @richgalloway.  I have been tasked with taking over our Splunk instance that a former employee started and never finished.

I will transition the inputs to apps so that I can use a DS.  One other thing. I see that the perfmon stanzas have "_meta = OS, OS version, IP, etc that are host specific.   When using a DS, how can I populate that data? 

 

0 Karma
Get Updates on the Splunk Community!

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...