官术网_书友最值得收藏!

Streaming data

Streaming data is almost always being generated, with a timestamp associated to each entry. Splunk's inherent ability to monitor and track data loaded from ever growing log files, or accept data as it arrives on a port, are critical pieces of functionality.

However, streaming data is no different than other data in that it's usefulness erodes, particularly at a detailed level. For instance, consider a firewall log.

In real time, Splunk will capture and index events written to a firewall log file. Normally, there will be many different activity events logged to Splunk in real time. However, many of those events are normal logging events noting activity occurring successfully.

As you consider your source data, its important to consider how long you want to retain data and/or how you would want to archive it. It is also important to understand if you need all the data from the source or only specific kinds of events.

主站蜘蛛池模板: 太谷县| 邵武市| 筠连县| 万全县| 阿合奇县| 南靖县| 衡阳市| 咸宁市| 平阴县| 贺兰县| 绥芬河市| 芦山县| 利辛县| 新河县| 榆中县| 临潭县| 清远市| 四子王旗| 遵义县| 抚远县| 仁寿县| 谢通门县| 新河县| 翁牛特旗| 互助| 澜沧| 宜宾市| 东辽县| 潞西市| 乐至县| 台前县| 申扎县| 宜黄县| 冀州市| 镇安县| 天全县| 忻城县| 金湖县| 大港区| 洪湖市| 榆林市|