Splunk® Light

Getting Started Manual

Download manual as PDF

Download topic as PDF

About adding data to Splunk Light

This section discusses options for getting data into Splunk Light. You can add data inputs from files and directories, network ports, scripted inputs, and from Splunk universal forwarders.

When you add data, the indexer processes it and stores it in an index. Indexes reside in flat files on your Splunk Light instance. By default, data you feed to an indexer is stored in the main index, but you can create and specify other indexes for different data inputs.

The Add Data page

There are different options for getting data into Splunk Light. Use the Add Data page to upload, monitor, or forward data. You can also configure an Add-on to add data to Splunk Light.

Upload

The Upload option lets you upload a file or archive of files for indexing. When you click Upload, Splunk Web goes to a page that starts the upload process. See:

Monitor

The Monitor option lets you monitor one or more files, directories, network streams, scripts, Event Logs (on Windows hosts only), performance metrics, or any other type of machine data that the Splunk Light instance has access to. When you click Monitor, Splunk Web loads a page that starts the monitoring process. See:

Note: The Splunk Light cloud service does not support monitoring inputs.

Forward

The Forward option lets you receive data from forwarders into your Splunk Light instance. When you click the "Forward" button, Splunk Web takes you to a page that starts the data collection process from forwarders. The Forward option requires configuration of a universal forwarder before the Forwarder page is populated. See:


Check the status of configured forwarders:

Use an Add-on to add data

To use an add-on to add data to Splunk Light, see Configure an Add-On to add data in Splunk Light in the Getting Started Manual.

PREVIOUS
Configure a Splunk Light password policy
  NEXT
About source types and input settings for Splunk Light

This documentation applies to the following versions of Splunk® Light: 6.5.0, 6.5.1, 6.5.2, 6.5.3, 6.5.1612 (cloud service only), 6.6.0, 6.6.1, 6.6.2, 6.6.3, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.3.0, 7.3.1, 7.3.2


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters