Getting Data In

can we convert the data gathered by TA unix and Linux to metrics Data and send it to metrics Index without using HEC?

sharmarohit123
Engager

We are using TA unix and Linux to get the data from UFs and wants this data to be converted into metrics data and to store it in custom metric index.

Is this feasible and how?

Tags (1)
0 Karma

niketn
Legend

@sharmarohit123 you should try to convert inputs.conf of existing *NIX TA and configure the same to write to metrics index instead.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

skalliger
Motivator

Hi,

either you switch the way you're collecting it or convert the data with mcollect into metrics format. Look here for more information.

Whether it's feasible or not depends on how much data you are searching on and what your use case is right now.

Skalli

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...