Configure: Splunk Enterprise


Configure Source


Data types available from Splunk Enterprise

Screen Shot 2021-04-23 at 3.11.49 PM.png

  1. Select data types (source supported data types will automatically be available in the UI; ensure Destination can ingest chosen data types

  2. Collector (Source Mediator)
    1. Event Data Type (Source)
    2. Metric Data Type (Source)
    3. Unstructured (Source)
    4. Topology Data Type (Source)

Access Event, Metric, and Topology Configuration Steps Through Expansion Panels Below


Step 6a: Configure Source Events



Step 6a: Configure Source Events

  1. Collection Schedule: the scheduled frequency which StreamWeaver will collect event data from Splunk (5 Minutes interval recommended)

  2. Data Time Window: the historical period from present time which StreamWeaver will collect from Splunk (5 Minutes interval recommended)

  3. Data Latency: specifies how far back on the timeline that the Data Time Window is placed

  4. Saved Search Name: A selection of Splunk Saved Searches (Reports) are automatically populated select one of the reports.

  5. Fields To Include (Not Used)

  6. Fields to Exclude (Not Used)

  7. Splunk Fields to Exclude : Select the splunk fields to exclude - All splunk fields are automatically selected, using the pull down a selection of unselected Splunk Fields is automatically populated from Elastic; select "Select All" or a specific subset of Statuses

Field Mappings

Carefully example the fields for the Elastic record and map them to the destination field names listed.

Screen Shot 2021-04-23 at 5.07.46 PM.png

Step 6b: Configure Source Metrics


Step 6b: Configure Source Metrics

  1. Collection Schedule: the scheduled frequency which StreamWeaver will collect event data from Splunk (5 Minutes interval recommended)

  2. Data Time Window: the historical period from present time which StreamWeaver will collect from Splunk (5 Minutes interval recommended)

  3. Data Latency: specifies how far back on the timeline that the Data Time Window is placed

  4. Saved Search Name: A selection of Splunk Saved Searches (Reports) are automatically populated select one of the reports.

Screen Shot 2021-04-23 at 5.42.14 PM.png

Step 6c: Configure Source Unstructured



Step 6c: Configure Source Unstructured

  1. Collection Schedule: the scheduled frequency which StreamWeaver will collect event data from Splunk (5 Minutes interval recommended)
  2. Data Time Window: the historical period from present time which StreamWeaver will collect from Splunk (5 Minutes interval recommended)

  3. Data Latency: specifies how far back on the timeline that the Data Time Window is placed

  4. Saved Search Name: A selection of Splunk Saved Searches (Reports) are automatically populated select one of the reports.

  5. Fields To Include (Not Used)

  6. Fields to Exclude (Not Used)

  7. Splunk Fields to Exclude : Select the splunk fields to exclude - All splunk fields are automatically selected, using the pull down a selection of unselected Splunk Fields is automatically populated from Elastic; select "Select All" or a specific subset of Statuses



Screen Shot 2021-04-23 at 5.51.44 PM.png

Step 6c: Configure Source Topology



Step 6d: Configure Source Unstructured

  1. Collection Schedule: the scheduled frequency which StreamWeaver will collect event data from Splunk (5 Minutes interval recommended)

  2. Data Time Window: the historical period from present time which StreamWeaver will collect from Splunk (5 Minutes interval recommended)

  3. Data Latency: specifies how far back on the timeline that the Data Time Window is placed

  4. Saved Search Name: A selection of Splunk Saved Searches (Reports) are automatically populated select one of the reports.

  5. Fields To Include (Not Used)

  6. Fields to Exclude (Not Used)

  7. Splunk Fields to Exclude : Select the splunk fields to exclude - All splunk fields are automatically selected, using the pull down a selection of unselected Splunk Fields is automatically populated from Elastic; select "Select All" or a specific subset of Statuses



Screen Shot 2021-04-23 at 5.54.54 PM.png

Click here to return to Step-by-Step Configuration Guide

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*

StreamWeaver 23.1.02