Splunk® App for Edge Hub

Install and Use Splunk App for Edge Hub

For documentation on other necessary components for Splunk Edge Hub, see the Splunk App for Edge Hub documentation, Splunk Edge Hub mobile app documentation, and Splunk Edge Hub hardware documentation.
This documentation does not apply to the most recent version of Splunk® App for Edge Hub. For documentation on the most recent version, go to the latest release.

Create indexes for Splunk App for AR and Edge Hub

Create indexes as part of the setup process for Splunk Edge Hub OS.

Prerequisite

Complete the steps at Prerequisites for Splunk Edge Hub OS in the Splunk Edge Hub OS Setup and Configuration Guide.

Create indexes for Splunk Edge Hub OS

Splunk Edge Hub OS produces metric and event data, so it requires both metric and event indexes. You'll configure these indexes using the Splunk App for Edge Hub and AR in a later step.

The following table lists the Splunk Edge Hub OS data groups, the index type they use, a description of the data groups, and their default index name:

Data group Description Index type Default index name
Sensors This is data related to internal sensors, external sensors and sensors configured through integrations, such as Message Queuing Telemetry Transport (MQTT). Metric edge_hub_data
Anomalies This data is related to anomalies detected on sensor data collected in Splunk Edge Hub OS by internally deployed AI models. Because anomalies are correlated with sensor metrics, they use the same edge_hub_data index used for sensors. A new index is not required for anomalies in the standard dashboards. Metric edge_hub_data
Health This data is related to the device itself in terms of CPU usage, CPU temperature, memory, and storage availability. Metric edge_hub_status
Logs All logs generated by the Splunk Edge Hub OS are delivered by this group. Event edge_hub_logs
SNMP The SNMP polling feature captures Simple Network management Protocol (SNMP) metrics delivered by this group. To learn more about configuring SNMP, see Collect and organize managed IP device information using the SNMP protocol. Event edge_hub_snmp
OPC-UA OPC-UA tags from configured OPC-UA servers are delivered by this group. To learn more about configuring OPC-UA, see Configure Splunk Edge Hub OS to connect to an OPC server. Event edge_hub_opcua
MODBUS This group delivers registered addresses from configured Modbus Transmission Control Protocol (TCP) servers. See Configure Splunk Edge Hub OS to communicate with electronic devices using the Modbus protocol. Event edge_hub_modbus
Splunk AR (Optional) If you're using Splunk AR, create this index to view details about your Splunk AR and Splunk Edge Hub deployment. Metric splunk_app_ar_metrics

Splunk Cloud Platform

To learn how to create indexes in Splunk Cloud Platform, See Manage Splunk Cloud Platform indexes in the Splunk Cloud Platform Admin Manual.

Splunk Enterprise

For single-instance deployments, create indexes on the single instance.

For distributed deployments, create indexes on the following nodes:

  • Indexers to store data
  • Heavy forwarder to configure the Splunk Edge Hub OS
  • Search head(s) to configure the pre-built dashboards

To learn how to create indexes on Splunk Enterprise, see Create custom indexes in the Splunk Enterprise Managing Indexers and Clusters of Indexers manual.

Next step

Create an event collector token where you've configured the HEC. See Create an event collector token for Splunk Edge Hub OS.

For an overview of installation and configuration steps, see Installation and configuration overview for Splunk Edge Hub OS in the Splunk Edge Hub OS Setup and Configuration Guide.

Last modified on 31 January, 2024
 

This documentation applies to the following versions of Splunk® App for Edge Hub: 4.5.0, 4.6.0, 4.7.1, 4.8.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters