Splunk® Enterprise

Getting Data In

Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Use Splunk Web

To use Splunk Web to add inputs from files and directories:

A. Go to the Add New page

You add an input from the Add New page in Splunk Web. You can get there by two routes:

  • Splunk Settings
  • Splunk Home

It doesn't matter which route you use; the Add New page itself is the same either way.

Via Splunk Settings:

1. Click Settings in the upper right-hand corner of Splunk Web.

2. In the Data section of the Settings pop-up, click Data Inputs.

3. Click Files & Directories.

4. Click the New button to add an input.

Via Splunk Home:

1. Click the Add Data link in Splunk Home.

2. Click the From files and directories link to add an input.

B. Preview your data

When you attempt to add a new directory or file input, Splunk Enterprise first gives you the option of previewing how your data will look once indexed. This allows you to make sure that Splunk Enterprise formats the data properly and to make any necessary adjustments to the event processing before the data gets committed to an index. If you don't want to preview your data, you can continue directly to the page where you add the new input.

See "Overview of data preview" to learn more about the data preview feature. See "View event data" for the procedure for accessing and using the data preview page.

If you choose to skip data preview, Splunk Web takes you directly to the Add new page where you can add your new input, as described in the next section.

C. Specify the input

1. Select a Source radio button:

  • Continuously index data from a file or directory this Splunk instance can access. Sets up an ongoing input. Whenever data is added to this file or directory, Splunk will index it. Read the next section for advanced options specific to this choice.
  • Upload and index a file. Uploads a file from your local machine into Splunk Enterprise.
  • Index a file once from this Splunk server. Copies a file on the server into Splunk Enterprise via the batch directory.

2. Specify the Full path to the file or directory. (If you selected the Upload a local file radio button, the field is called File instead.)

To monitor a shared network drive, enter the following: <myhost>/<mypath> (or \\<myhost>\<mypath> on Windows). Make sure Splunk Enterprise has read access to the mounted drive, as well as to the files you wish to monitor.

3. To access other settings, check More settings. A number of additional settings appear. You can usually go with the defaults for these settings. If you want to set them explicitly, here's what they're for:

a. Under the Host section, you can set the host name value. You have several choices for this setting. Learn more about setting the host value in "About hosts".
Note: Host only sets the host field in the resulting events. It does not direct Splunk Enterprise to look on a specific host on your network.
b. You can set the Source type. Source type is a default field added to events. Source type is used to determine processing characteristics, such as timestamps and event boundaries. For information on how to override automatic source typing, see "Override automatic source type assignment" in this manual.
For directories, set the source type to Automatic. If the directory contains files of different formats, do not set a value for the source type manually. By doing so, you'll force a single source type for all files in that directory.
c. You can set the Index for this input. Leave the value as "default", unless you have defined multiple indexes to handle different types of events. In addition to indexes for user data, Splunk has a number of utility indexes, which also appear in this dropdown box.

4. Click Save.

Advanced options for file/directory monitoring

If your selected the Monitor a file or directory radio button for your source, the More settings section also includes an Advanced options section, which allows you to configure some additional settings:

  • Follow tail. If checked, monitoring begins at the end of the file (like *nix tail -f).
  • Whitelist. If a path is specified, files from that path are monitored only if they match the specified regular expression.
  • Blacklist. If a path is specified, files from that path are not monitored if they match the specified regular expression.

For detailed information on whitelists and blacklists, see Whitelist or blacklist specific incoming data in this manual.

Last modified on 02 September, 2014
Monitor files and directories
Monitor files and directories with the CLI

This documentation applies to the following versions of Splunk® Enterprise: 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14, 6.0.15, 6.1, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12, 6.1.13, 6.1.14

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters