Splunk® Light

Getting Started Manual

Download manual as PDF

This documentation does not apply to the most recent version of SplunkLight. Click here for the latest version.
Download topic as PDF

About adding data

This section discusses options for getting data into Splunk Light and the Splunk Light cloud service. You can add data inputs from files and directories, network ports, scripted inputs, and from Splunk universal forwarders.

When you add data, the indexer processes it and stores it in an index. Indexes reside in flat files on your Splunk Light instance. By default, data you feed to an indexer is stored in the main index, but you can create and specify other indexes for different data inputs.

How to add data

In Splunk Light, use the Add Data view to Upload files from your computer, Monitor files and ports on this Splunk indexer, and Forward data from a universal forwarder. The Splunk Light cloud service does not support Monitor inputs.

SplunkLight adddata.png

The following topics provide examples of adding different types of data into Splunk Light.

Access your Data settings

You can use the sidebar navigation to access your Data settings for Add-Ons, Data inputs, Receiving, and Indexes.

The Add-Ons view displays all the Splunk Light compatible add-ons that you have downloaded on your instance. You can use this view to install, enable and disable, or browse for new add-ons. The Splunk Light cloud service does not support add-ons.

The Data inputs view displays all the data sources that you have added to this Splunk Light instance. You can enable, disable, and add new data inputs from this view, too.

The Receiving view displays your configuration for receiving data from one or more Splunk Forwarders. You can also view the receiving data as an input in the Data inputs view.

The Indexes view displays all the indexes you have on this Splunk Light instance. You can enable or disable indexes and create custom indexes from this view.

Manage account settings
About source types and input settings

This documentation applies to the following versions of Splunk® Light: 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters