Creating Splunk Input Data Source
The Splunk connector allows the retrieval of data from a Splunk instance.
Steps:
1. In the New Data Source page, select Input > Splunk in the Connector drop-down list.
2. Enter the connection details including:
Property |
Description |
Host |
Splunk host address. |
Port |
Splunk host port. Default is 8089. |
User Id |
The user Id that will be used to connect to the Splunk service. |
Password |
The password that will be used to connect to the Splunk service. |
3. Select the Search Type:
· Manual
Proceed to step 6 to define a new search query.
· Saved Search
Allows you to select in the Saved Search drop-down list.
4. Click to populate the Application drop-down list and select one.
5. Select whether the parameters should be automatically enclosed in quotes by selecting the Enclose parameters in quotes check box.
6. Enter a Search Query.
7. Click . The new data source is added in the Data Sources list.