Splunk Search

How do I automate the indexing and field extraction process?

minkyuk
Explorer

Good morning,

For the past few days, I have been putting log files through an indexer and extracted some fields manually.

However, I want to automate this process where log files are generated automatically at a certain directory. I am stuck on how to perform this task. (Daily scheduled event perhaps?)

If anyone has any idea on this matter, I would appreciate your input.

Thanks,
Jack

0 Karma

woodcock
Esteemed Legend

It is very straightforward, start here and it should be easy:

http://docs.splunk.com/Documentation/Splunk/6.2.4/Data/Monitorfilesanddirectories

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...