If you want to monitor files and network ports on your Splunk Enterprise instance, navigate to the Monitor page in Splunk Web:
- From the Splunk Web system bar, click Settings.
- Choose the Add Data page.
- Click the Monitor page.
The Monitor page
From the Monitor page, choose the type of data that you want Splunk Enterprise to monitor. Default inputs appear first, followed by forwarded inputs, then any modular inputs that are on the instance.
The Monitor page shows only the types of data sources that you can monitor, which depends on the type of Splunk deployment you have. If you're running Splunk Enterprise, the page also shows you the platform that the instance runs on. See Types of data sources for more information on what Splunk Enterprise can monitor.
Add a data input
Some data sources are available only on certain operating systems. For example, Windows data sources are available only on machines that run Windows. Splunk Cloud cannot monitor Windows inputs directly because it doesn't run on Windows, but you can forward data from a universal forwarder that runs Windows to Splunk Cloud.
- Select a source by clicking it once. The page updates based on the source you selected.
- Follow the on-screen prompts to complete the selection of the source object that you want to monitor.
- Click Next to proceed to the next step in the Add data process.
If you experience problems with these steps, the logged-in Splunk user account might not have permissions to add data or see the data source that you want to add.
This documentation applies to the following versions of Splunk® Enterprise: 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.2.9, 7.2.10, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 7.3.9, 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.0.7, 8.0.8, 8.0.9, 8.1.0, 8.1.1, 8.1.2, 8.1.3