Documentation: 3.1.5
Print Version Contents
This page last updated: 10/18/07 03:10pm

Configure inputs via SplunkWeb

Follow these instructions to configure data inputs via SplunkWeb. You can also configure data inputs via Splunk's CLI or inputs.conf.

Configuration

  • Click Admin in the upper-right of the SplunkWeb interface.

http://www.splunk.com/assets/doc-images/30_admin4_configinputsweb/admin.jpg

  • Then click the Data Inputs Tab. You will see a list with the following input catagories:

http://www.splunk.com/assets/doc-images/30_admin4_configinputsweb/inputs.jpg

  • All - Display and access to the following data inputs catagories:
    • FIles & Directories - Display and access configuration of each path that is being read by Splunk.
    • FIFO Queues - Display and access configuration of each FIFO that is being processed by Splunk.
    • Network Ports - Display and access configuration for UDP and TCP ports.
  • Click the Add Inputs Actions link next to each category to configure new inputs.
  • Click the Data Input tab to edit existing configurations or add new inputs. You can choose from the following configuration options.

Files and directories

  • Click Admin in the upper-right of the SplunkWeb interface. Then click the Data Inputs Tab. You will see a listing of the Data Input types.
  • Click the Add Inputs link to the right of the Files & Directories listing.

http://www.splunk.com/assets/doc-images/30_admin4_configinputsweb/tail.jpg

  • Under the Source heading, specify the Data Access method:
    • Tail
    • Spool
    • Upload
    • Watch and Copy
    • Watch and symlink
  • Then, specify the pathname to the file or directory. If you select the Upload method, you are presented with a Browse... button.
  • Under the Host heading, select the host name that will be stored as metadata with the events. You have several choices if you are using Tail or Watch methods. Learn more about setting host value.
  • Now set the Source Type. Source type is an important piece of metadata added to events. Source type is used to determine processing characteristics such as timestamps and event boundaries. Learn more about setting source type.
  • After specifying the source, host, and source type, click the Add button.

FIFO queues

  • Click Admin in the upper-right of the SplunkWeb interface. Then click the Data Inputs Tab. You will see a listing of the Data Input types.
  • Click the Add Input action link to the right of the FIFO Queue listing.

http://www.splunk.com/assets/doc-images/30_admin4_configinputsweb/fifo.jpg

  • Under the Source heading, type in the path to the FIFO.
  • Under the Host heading, accept the default host name or enter a new hostname or ip address.
  • Under the Source Type heading make one of these choices:
    • Select From List to chose one of the pre-defined source types. Select the type from the drop-down list.
    • Select Manual to define your own Source Type. Type the source type name in the text box.
  • Click the Add button.

Network ports

With a Splunk Enterprise license, you can can define input from any TCP or UDP port.

To add Network Ports:

  • Click Admin in the upper-right of the SplunkWeb interface. Then click the Data Inputs Tab. You will see a listing of the Data Input types.
  • Click Add Input to the right of Network Ports listing.

http://www.splunk.com/assets/doc-images/30_admin4_configinputsweb/ports.jpg

  • Under the Source heading, select Protocol of UDP or TCP.
  • Accept the default port, 9998, or enter another port number.
  • Specify whether this port should accept connections from all hosts or one host.
    • If you specify one host, enter the IP address of the host.
  • Under the Source Type heading make one of these choices:
    • Select From List to chose one of the pre-defined source types. Select the type from the drop-down list.
    • Select Manual to define your own Source Type. Type the source type name in the text box.
  • Click the Add button.

Comments

No comments have been submitted.

Log in to comment.