Add script for docker events/metrics and support running TA outside of Splunk
* Add docker.sh and docker_metric.sh for collecting docker events/metrics * Add helper script to extra/ to run the TA commands on systems without a Splunk forwarder. The commands can be sent to a syslog server. This script is useful for systems with small or read-only filesystems that cannot support a Universal Forwarder. * Add syslog_inputs_nix_ta app to extra/ for ingesting the data from syslog
This commit is contained in:
parent
5e766d84d5
commit
5551b8973d
13 changed files with 322 additions and 13 deletions
|
@ -91,6 +91,15 @@ FIELDALIAS-dest_nt_host = dest_host as dest_nt_host
|
|||
## Scripted Metric Inputs
|
||||
#########################
|
||||
|
||||
[docker_metric]
|
||||
SHOULD_LINEMERGE=false
|
||||
LINE_BREAKER = ([\r\n]+)
|
||||
KV_MODE = json
|
||||
NO_BINARY_CHECK = true
|
||||
TRUNCATE=1000000
|
||||
TRANSFORMS-docker-metric-dimensions=eval_dimensions
|
||||
METRIC-SCHEMA-TRANSFORMS=metric-schema:extract_metrics_docker
|
||||
|
||||
[vmstat_metric]
|
||||
SHOULD_LINEMERGE=false
|
||||
LINE_BREAKER=(^$|[\r\n]+[\r\n]+)
|
||||
|
@ -506,6 +515,14 @@ TRUNCATE=1000000
|
|||
DATETIME_CONFIG = CURRENT
|
||||
KV_MODE=multi
|
||||
|
||||
[docker]
|
||||
SHOULD_LINEMERGE=false
|
||||
LINE_BREAKER=(^$|[\r\n]+[\r\n]+)
|
||||
TRUNCATE=1000000
|
||||
KV_MODE = json
|
||||
FIELDALIAS-dest_for_docker = host as dest
|
||||
FIELDALIAS-src_for_docker = host as src
|
||||
|
||||
[vmstat]
|
||||
LINE_BREAKER=(^$|[\r\n]+[\r\n]+)
|
||||
TRUNCATE=1000000
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue