Splunk App for Unix and Linux

noun

A Splunk app for Linux and Unix management. Provides pre-built data inputs, searches, reports, alerts and dashboards that let you monitor, manage and troubleshoot *nix operating systems from one place. Includes scripted inputs for collecting CPU, disk, I/O, memory, log, configuration and user data; saved event types, macros, and searches; and multiple dashboards and views. Enabling the app automatically authorizes it to start collecting data on your system. Can be downloaded from the Splunk website or accessed from the Launcher.

For more information

On Splunkbase::

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time