scripted input

noun

A method of getting event data into Splunk from APIs and other remote data interfaces and message queues, data which can then be used to generate metrics and status information through command-line tools such as vmstat, lostat, iostat, and netstat.

Scripted inputs are used to get data from Active Directory, WMI (Windows Management Interface), Registry, and other Windows data sources. You can also download additional apps from SplunkBase that use scripted inputs to enable data collection from other applications.

You can configure your own scripted inputs from Splunk Manager, or by editing inputs.conf directly.

For more information

In the Getting Data In Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time