Dowload Splunk: https://splunkbase.splunk.com/app/1546/#/overview
Download Splunk REST Modular API" https://www.splunk.com/blog/2013/06/18/getting-data-from-your-rest-apis-into-splunk.html
On local
scp rest-api-modular-input_14.tgz [email protected]:/opt/splunk/etc/apps
On server
cd /opt/splunk/etc/apps
tar zxvf rest-api-modular-input_14.tgz
Start Splunk
/opt/splunk/bin/splunk help simple
/opt/splunk/bin/splunk {start|stop|restart|status}
Error log
tail -f /opt/splunk/var/log/splunk/splunkd.log
Splunk */5 * * * *
/opt/splunk/etc/system/default/
Cron format: https://crontab.guru/
Splunk CLI: http://docs.splunk.com/Documentation/Splunk/6.6.2/Admin/AbouttheCLI
http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/Commontimeformatvariables
imestamp extraction:
TIME_FORMAT=%s%3N
https://answers.splunk.com/answers/4092/extract-timestamp-in-epoch-milliseconds-to-date.html
ttp://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/Commontimeformatvariables
Data Archiving Policy: https://docs.splunk.com/Documentation/Splunk/6.6.3/Indexer/Setaretirementandarchivingpolicy
Remove Data: http://docs.splunk.com/Documentation/Splunk/6.6.2/Indexer/RemovedatafromSplunk
Splunk on NGINX https://www.splunk.com/blog/2017/02/20/ssl-proxy-splunk-nginx.html