Latest Version 1.0
January 22, 2016
This app is archived.
For comparing indexer performance, understanding operators, or log levels (INFO .. CRIT), you have to leverage search.log. Indexing it isn't scalable though. This app will, every five minutes, launch a scripted input that will review the local dispatch directory for any search.log files, and the parse out the details into a JSON blob that will be put in index=_internal.
(0)
Categories
Created By
Type
Downloads
Licensing
Splunk Answers
Resources