Welcome to InsightFinder!
Sign up for an account with InsightFinder
- Go to InsightFinder Signup
Register a Splunk project in InsightFinder
- Sign in to InsightFinder with your user credentials
- Go to Settings and add a new project (Top icon on the left side of your screen) under the "Insight Agent" tab
- Give your project a name, select "Private Cloud" for project type,
- Select "data type" to be either "metric" or "log"
- Select "agent type" to be "Splunk"
- Go to Account Info (Note: click on your user ID in the top right corner of the screen) and note your license key number and enter it in the configuration file: $SPLUNK_HOME/etc/apps/insightfinderapp/default/insightfindersetting.cfg'
- An example configuration file is as fllows:
[SETTINGS] SERVER_URL=https://app.insightfinder.com USERNAME=YOUR USER NAME in InsightFinder LICENSEKEY=YOUR LICENSE KEY in your InsightFinder account profile CHUNKSIZE=200
If your are an on-prem customer, please replace SERVER_URL with your InsightFinder app server URL. The CHUNKSIZE denotes the size (in KB) of each data block transmitted from your Splunk App to the InsightFinder app server. Please make sure the chunk size is allowed by your local network configuration and within the jetty configuration limitation on InsightFinder app server. https://agent-data.insightfinder.com currently can accept the chunk size below 500KB.
For log streaming analysis, a sample query looks like this
index="_internal" source="/opt/splunk/var/log/splunk/logData.log" | reportmetrics projectName=YOUR_PROJECT_NAME mode=LogStreaming
For log replay analysis, a sample query looks like this
index="_internal" source="/opt/splunk/var/log/splunk/logData.log" | reportmetrics projectName=YOUR_PROJECT_NAME mode=LogReplay
For metrics streaming analysis, a query looks like this:
index="_internal" source="/opt/splunk/var/log/splunk/metrics.log" | rename YOUR_TIMESTAMP_NAME as _time | rename YOUR_HOST_NAME as host | table _time host instantaneous_eps average_kbps instantaneous_kbps | reportmetrics projectName=YOUR_PROJECT_NAME mode=MetricStreaming
For metrics replay analysis, a query looks like this:
index="_internal" source="/opt/splunk/var/log/splunk/metrics.log" | rename YOUR_TIMESTAMP_NAME as _time | rename YOUR_HOST_NAME as host | table _time host instantaneous_eps average_kbps instantaneous_kbps | reportmetrics projectName=YOUR_PROJECT_NAME mode=MetricReplay
This command reports
instantaneous_kbps. Please make sure timestamp is named as
_time and the host name is named as
host. You can use the rename command to meet the naming requirements.
- Download the installation file by clicking "Download" on the InsightFinder Splunkbase Page.
- Unpack the contents into
- After unpacking, you should see the directory in:
We’ll refer to this directory as $INSIGHTFINDER_HOME in future instructions.
- Configure the file
$SPLUNK_HOME/etc/apps/insightfinderapp/default/insightfindersetting.cfg using the instrutions given above.
Updated scripts sending data to and fetching data from InsightFinder server.
Splunk's App Certification program uses a specific set of criteria to evaluate the level of quality, usability and security your app offers to its users. In addition, we evaluate the documentation and support you offer to your app's users.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 50GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.