Splunk Enterprise
Splunk Enterprise as Data Source
Prerequisites:
cd /opt/splunkforwarder/etc/system/local
Edit inputs.conf
Add the below line to add additional fields
_meta = key1::value1 key2::value2
Eg: _meta = ipaddress::10.95.131.23 hostname::cfx-wpress-db01.demo.cloudfabrix.com
Restart splunk agent
/opt/splunkforwarder/bin/splunk stop
/opt/splunkforwarder/bin/splunk startEnabling API Port 8089
Addition of Splunk Enterprise as DataSource
Adding Splunk Enterprise Data Source in the Incident Room
Creating Alert Source for Splunk Enterprise
Table describing the field mappings between Splunk Alert Payload and Alert Watch Fields.
Last updated