March 2018
Beginner to intermediate
576 pages
13h 29m
English
The vast majority of events in Splunk come from files. Usually, these events are read from the machine where they are produced and as the logs are written. Very often, the entire input's stanza will look like this:
[monitor:///logs/interesting.log*] sourcetype=interesting
This is often all that is needed. This stanza says:
These are usually perfectly acceptable defaults. If sourcetype is omitted, Splunk will pick a default ...
Read now
Unlock full access