Getting Data into Splunk is made significantly more simple through the use of a custom app. This video will demonstrate how to ingest data into Splunk through the creation of a custom props.conf and inputs.conf that will be contained in a custom app. This is part one of a playlist. Please refer to the link below for the complete playlist on data ingestion.
00:00 Splash Screen
00:11 Intro
03:45 Sample data for data ingestion
04:24 Creating your custom app TA
06:00 Add Data Tool - json log
07:35 Creating your own datasource
10:20 Add Data Toll - CSV log
12:40 Viewing the Props.conf files created during Add Data
14:06 Set up file monitoring
17:25 Viewing the inputs.conf files created during file monitoring
19:29 Changing monitoring file path for your universal forwarder log location
This video is part of a playlist on how to ingest data into Splunk. For the full playlist click the following link
• Ingesting Data into Splunk
Join this channel to get access to early release of videos and exclusive training videos that will help make you L.A.M.E. ninja: / @lamecreations_guides
Visit our discord channel to post questions and suggestions for what you want to learn. / discord
The latest L.A.M.E. Splunk apps are available at
https://www.github.com/lameCreations