Splunk® Enterprise

Getting Data In

Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Monitor data

This topic explains the page that Splunk Enterprise loads when you select the "Monitor" button on the "Add data" page.

The "Monitor" page

When you access the "Monitor" page, Splunk Enterprise presents you with the following:

62 SelectSource Monitor.png

This page lets you choose the type of data that Splunk Enterprise should monitor. Splunk Enterprise lists the default inputs first. It then lists forwarded inputs below the default inputs. Finally,it shows any modular inputs you have installed on the instance.

To monitor data, perform the following steps:

1. Select a source from the left side of the screen by clicking it once.

Splunk Enterprise updates the rest of the page with controls that are specific to the source you selected. For example, if you select "Files & Directories", the page updates with a field to enter a file or directory name and specify how Splunk Enterprise should monitor the file or directory.

Note: Splunk Enterprise shows only sources that it has the capability of monitoring. Refer to the list of data sources for specifics. If you do not see the data source that you want to monitor, consider the following reasons:

  • Some data sources are available only on certain operating systems. For example, all Windows data sources are not available on a Splunk Enterprise instance that runs on *nix (and vice versa).
  • The user you logged into Splunk Enterprise with might not have permissions to add data or see the data source.

2. Follow the on-screen prompts to complete the selection of the source object that you want Splunk Enterprise to monitor.

3. Click the green Next button on the upper right to proceed to the next step in the "Add data" process.

Last modified on 22 April, 2015
Upload data
Forward data

This documentation applies to the following versions of Splunk® Enterprise: 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.2.10, 6.2.11, 6.2.12, 6.2.13, 6.2.14, 6.2.15

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters