I know that obviously I can obtain information in real time by getting information from the target Splunk server with an application such as add on for linux.
However, I want a function to know the system information of the target Splunk server by indexing diag file to another Splunk server.
If anyone has a good idea,
please tell me.
Diag can be imported into Splunk as it is. try it.
Yeah I know diag can be imported as it is, and the internal type log is configured automatically in each appropriate sourcetypes, but systeminfo.txt is separated to each event complicatedly.
どんな情報を取得したいんですか?
sourcetype=systeminfo
で検索すれば情報がまとまっていると思いますが、どのように分離していますか?