
Monitor data
This topic explains the page that Splunk Enterprise loads when you select the "Monitor" button on the "Add data" page.
The "Monitor" page
When you access the "Monitor" page, Splunk Enterprise presents you with the following:
This page lets you choose the type of data that Splunk Enterprise should monitor. Splunk Enterprise lists the default inputs first. It then lists forwarded inputs below the default inputs. Finally,it shows any modular inputs you have installed on the instance.
To monitor data, perform the following steps:
1. Select a source from the left side of the screen by clicking it once.
- Splunk Enterprise updates the rest of the page with controls that are specific to the source you selected. For example, if you select "Files & Directories", the page updates with a field to enter a file or directory name and specify how Splunk Enterprise should monitor the file or directory.
Note: Splunk Enterprise shows only sources that it has the capability of monitoring. Refer to the list of data sources for specifics. If you do not see the data source that you want to monitor, consider the following reasons:
- Some data sources are available only on certain operating systems. For example, all Windows data sources are not available on a Splunk Enterprise instance that runs on *nix (and vice versa).
- The user you logged into Splunk Enterprise with might not have permissions to add data or see the data source.
2. Follow the on-screen prompts to complete the selection of the source object that you want Splunk Enterprise to monitor.
3. Click the green Next button on the upper right to proceed to the next step in the "Add data" process.
PREVIOUS Upload data |
NEXT Forward data |
This documentation applies to the following versions of Splunk® Enterprise: 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.2.10, 6.2.11, 6.2.12, 6.2.13, 6.2.14, 6.2.15
Feedback submitted, thanks!