Create indexes for Splunk Edge Hub Software
The Splunk platform indexes 2 types of data: events and metrics. Events are records of machine data activity. Metrics are measurements captured from the technology infrastructure, security systems, and business applications in real time.
The Splunk Edge Hub Software organizes data into separate groups. These data groups determine whether an event or metric index type is used. You must create these indexes as part of the set up process. To learn more about the Splunk Edge Hub Software set up process, see Get started with Splunk Edge Hub Software.
To learn more about event processing, see Overview of event processing in the Splunk Enterprise Getting Data In manual. To learn more about metrics, see Overview of metrics in the Splunk Cloud Platform Metrics manual.
About Splunk Edge Hub Software data groups
The Splunk App for Edge Hub Software and AR provides standard dashboards that use default index names for each data group.
The following table lists the Splunk Edge Hub Software data groups, the index type they use, a description of the data groups, and their default index name:
Data group | Description | Index type | Default index name |
---|---|---|---|
Sensors | This is data related to internal sensors, external sensors and sensors configured through integrations, such as MQTT. | Metric | edge_hub_data
|
Anomalies | This is data related to anomalies detected on sensor data collected in the Splunk Edge Hub Software by internally deployed AI models. Because Anomalies are correlated with sensor metrics, they use the same edge-hub-data index used for sensors. A new index is not required for anomalies in the standard dashboards. | Metric | edge_hub_data
|
Health | This data is related to the device itself in terms of CPU usage, CPU temperature, memory, and storage availability. | Metric | edge_hub_status
|
Logs | All logs generated by the Edge Hub Software are delivered by this group. | Event | edge_hub_logs
|
SNMP | The SNMP polling feature captures SNMP metrics delivered by this group. To learn more about configuring SNMP, see Collect and organize managed IP device information using the SNMP protocol. | Event | edge_hub_snmp
|
OPC-UA | OPC-UA tags from configured OPC_UA servers are delivered by this group. To learn more about configuring OPC-UA, see Configure Splunk Edge Hub Software to connect to an OPC server. | Event | edge_hub_opcua
|
Create indexes for Splunk Edge Hub Software
When you create indexes for Splunk Edge Hub Software, the index names will be pre-populated when you create the indexes. To learn how to create indexes on your Splunk platform, see Create custom indexes in the Splunk Enterprise Managing Indexers and Clusters of Indexers manual.
This documentation applies to the following versions of Splunk® Edge Hub OS: beta1.3.1, beta1.3.2
Feedback submitted, thanks!