Splunk Enterprise

Is there a way to format systeminfo.txt contained in diag to a form that can be seen in Splunk?

yutaka1005
Builder

I know that obviously I can obtain information in real time by getting information from the target Splunk server with an application such as add on for linux.

However, I want a function to know the system information of the target Splunk server by indexing diag file to another Splunk server.

If anyone has a good idea,
please tell me.

0 Karma

HiroshiSatoh
Champion

Diag can be imported into Splunk as it is. try it.

0 Karma

yutaka1005
Builder

Yeah I know diag can be imported as it is, and the internal type log is configured automatically in each appropriate sourcetypes, but systeminfo.txt is separated to each event complicatedly.

0 Karma

HiroshiSatoh
Champion

どんな情報を取得したいんですか?
sourcetype=systeminfo
で検索すれば情報がまとまっていると思いますが、どのように分離していますか?

0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...