Splunk® Supported Add-ons

Splunk Add-on for Box

Configure File Ingestion Input for the Splunk Add-on for Box

To configure File Ingestion inputs for the Splunk Add-on for Box, complete these steps:

  1. On Splunk Web, go to the Splunk Add-on for Box, either by selecting the name of the add-on on the navigation banner, or by going to Manage Apps then selecting Launch App in the Splunk Add-on for Box section.
  2. Select Inputs.
  3. Select Create new input and then select File Ingestion Input.
  4. Fill in the required fields:
    Field Description
    Name A name for the new input
    Box account The Box account with permissions for the input. Ensure you have set up the add-on to work with this Box account.
    File/Folder ID Enter the File/Folder ID found in the Box portal URL (e.g., https://app.box.com/folder/123456789), where the numbers at the end represent the ID.
    Interval How often, in seconds, the Splunk platform calls the API to collect data for a metric. This value overrides the configuration of the default collection interval in the setup screen. The default interval value is set to 86400 seconds.
    Index The index in which the Splunk platform stores events from Box. The default is main.

    The following file extensions are supported for file ingestion input: .json, .xml, .csv, .txt, .text, and .log. Files with other extensions will not be ingested.

    • JSON Files: Each JSON object will be ingested as a separate event in Splunk.
    • XML Files: Only valid XML content will be ingested as a single event in Splunk. If the XML content is invalid, the file will not be ingested.
    • CSV Files: Each row in the CSV file will be ingested as a separate event in Splunk.

Last modified on 06 December, 2024
Configure Live Monitoring Inputs for the Splunk Add-on for Box   Troubleshoot the Splunk Add-on for Box

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters