1. Install the add-on. In a distributed environment, install the add-on on your forwarders, indexers, and search heads.
2. On your data collection node, usually a forwarder, create a new TCP input.
3. Set the source type for the input to kepware:idf.
4. Specify a metrics index for your Kepware IDF data.
5. Save the input and restart the forwarder if necessary.
4. Configure Kepware's IDF to forward data to the TCP port you specified for the input. See the Kepware documentation at https://www.kepware.com/en-us/products/kepserverex/advanced-plug-ins/industrial-data-forwarder-splunk/.
5. To test that data ingestion is working, access your search head and run a search for sourcetype=kepware:idf
To use the dashboard in this add-on:
1. Launch the add-on on your search head and click Tag Discovery.
2. In the Index drop-down, select the metric index from step 4 above.
3. In the Metrics drop down, select a few metrics to visualize them on a graph.
Updated Regular expression for Metric_Name
Adjusted regex to accept spaces
Updated time extraction to include zulu time.
Updated so that meta data is parsed out as metadata.
Remove special characters from incoming data that affect the data going into metrics.
Updated the extraction to include "_", "(", and ")"
Updated Tag discovery to include Tag names that include spacing.
Added a quick start guide.
More detailed testing dashboard.
Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.