Get started with metrics - Splunk Documentation (2024)

The Splunk platform gathers metrics from different sources and stores this data into a new type of index that is optimized for ingestion and retrieval of metrics.

The Splunk platform supports the following metrics-gathering tools natively:

Both of these tools are lightweight and easy to use, and they have a large community of support. If you want to start gathering performance metrics from your applications and systems, review these tools to determine whether either of them suits your environment.

If you prefer to use a different metrics-gathering tool, you can still use the Splunk platform to collect and analyze your data with manual configuration.

Metrics data format

Metrics data uses a specific format with the following fields. Each of these fields is required, unless they are identified as optional.

FieldWritable or InternalDescriptionExample
_timeWritableThe timestamp of the metric in UNIX time notation.1504907933.000
metric_name:<metric_name>WritableThe metric name. It always has a numeric value. This is a 64-bit floating point number, which supports precision between 15 and 17 decimal digits.metric_name:os.cpu.user=42.12345
<dimension0> ...
<dimensionn>
WritableAn arbitrary number of dimension fields that indicate how metrics can be split.ip
_dimsInternalAn auto-generated internal field that contains the names of all of the dimensions in the metric event. The purpose of this field is to return a list of unique dimension names in a metrics index._dims::ip
source (optional)InternalThe source of the metrics data.udp:8125
hostInternalThe origin host. A standard field in Splunk software.server007
indexInternalThe metrics index name. A standard field in Splunk software.metricsindex
sourcetypeInternalThe data structure of the metric. A standard field in Splunk software.statsd

The Splunk platform cannot index metric data points that contain metric_name fields which are empty or composed entirely of white spaces.

Supported line protocols

Metrics in the Splunk platform natively supports the following metric line protocols:

  • Plain StatsD over UDP/TCP
  • The StatsD extension with dimensions over UDP/TCP
  • Collectd over HTTPS using HTTP Event Collector (HEC)

For details about getting data in, see Get metrics in from StatsD and Get metrics in from collectd.

To support other line metric protocols, you can use custom transformations to get metrics data into Splunk platform from other tools. For details, see Get metrics from other clients.

Metrics source types

The Splunk platform includes the following pre-trained source types to support the most widely-supported line metric protocols:

Source type nameDescription
statsdSupports data using the metric line protocols for plain StatsD and the StatsD extension with dimensions.
collectd_httpSupports data using the metric line protocol for collectd.
metrics_csvSupports data in CSV format. For usage details, see Get metrics in from other sources.

Metrics indexes

To store and analyze metrics data as efficiently as possible, metrics data is stored in a type of index just for metrics. Metrics indexes store metric data points in a format that provides faster search performance and more efficient data storage than you will find with events in event indexes.

A metrics index can be used only for metrics data. You cannot convert an events index to a metrics index, or vice versa.

You can monitor internal Splunk metrics in the default _metrics index. It is a metrics analog of the _internal event index.

If you use Splunk Enterprise, see Create metrics indexes in the Managing Indexers and Clusters of Indexers manual.

If you use Splunk Cloud Platform, see Manage Splunk Cloud Platform indexes in the Splunk Cloud Platform Admin Manual.

For information about how metrics data is metered, see How Splunk Enterprise licensing works in the Admin Manual.

Default metrics indexes

You can assign default metrics indexes to user roles. See Add and edit roles with Splunk Web in Securing Splunk.

When you run a search with metrics commands such as mcatalog or mstats and you do not filter the search by a specific index, the search automatically searches the default indexes assigned to your role. If you run a metrics search that does not filter by a specific metrics index and you have no default metrics indexes assigned to your role, the metrics search runs over an empty dataset.

Search and CLI commands with metrics

  • To analyze metric data and enumerate items in a metrics index, use the mstats and mcatalog search commands.
  • The mpreview command enables you to view individual metric data points, without aggregation.
  • The mcollect and meventcollect commands convert event log data into metric data points at search time.

Other search commands that work with events do not work with metrics. For example, the delete command does not work with metrics. For more about searching a metrics index, see Search and monitor metrics.

Administrative CLI commands may not all work with metrics. You can use commands such as add index and list index with metrics when using the -datatype metric parameter. See Create metrics indexes in the Managing Indexers and Clusters of Indexers manual.

Get started with metrics - Splunk Documentation (2024)
Top Articles
M.J. Colucci & Son Funeral Chapel | Obituaries
Arthur to roll out its massive automated fireworks show
Menards Thermal Fuse
Koopa Wrapper 1 Point 0
Hannaford Weekly Flyer Manchester Nh
Pga Scores Cbs
Alan Miller Jewelers Oregon Ohio
Lighthouse Diner Taylorsville Menu
Top 10: Die besten italienischen Restaurants in Wien - Falstaff
DENVER Überwachungskamera IOC-221, IP, WLAN, außen | 580950
Jonathan Freeman : "Double homicide in Rowan County leads to arrest" - Bgrnd Search
Victoria Secret Comenity Easy Pay
Best Theia Builds (Talent | Skill Order | Pairing + Pets) In Call of Dragons - AllClash
More Apt To Complain Crossword
Craigslistdaytona
Prices Way Too High Crossword Clue
Milk And Mocha GIFs | GIFDB.com
Brutál jó vegán torta! – Kókusz-málna-csoki trió
N2O4 Lewis Structure & Characteristics (13 Complete Facts)
Ms Rabbit 305
Wsop Hunters Club
Is A Daytona Faster Than A Scat Pack
Parc Soleil Drowning
Talk To Me Showtimes Near Marcus Valley Grand Cinema
Walgreens Bunce Rd
Danielle Ranslow Obituary
Scripchat Gratis
Abga Gestation Calculator
Superhot Free Online Game Unblocked
950 Sqft 2 BHK Villa for sale in Devi Redhills Sirinium | Red Hills, Chennai | Property ID - 15334774
Imagetrend Elite Delaware
Amazing Lash Bay Colony
Why Are The French So Google Feud Answers
Restaurants Near Calvary Cemetery
Vistatech Quadcopter Drone With Camera Reviews
Stolen Touches Neva Altaj Read Online Free
Metro By T Mobile Sign In
Myfxbook Historical Data
Bismarck Mandan Mugshots
Banana Republic Rewards Login
Hindilinks4U Bollywood Action Movies
M Life Insider
COVID-19/Coronavirus Assistance Programs | FindHelp.org
Levi Ackerman Tattoo Ideas
Martha's Vineyard – Travel guide at Wikivoyage
The Average Amount of Calories in a Poke Bowl | Grubby's Poke
Acuity Eye Group - La Quinta Photos
Pronósticos Gulfstream Park Nicoletti
How to Do a Photoshoot in BitLife - Playbite
Craigslist Com Brooklyn
Glowforge Forum
Hcs Smartfind
Latest Posts
Article information

Author: Jeremiah Abshire

Last Updated:

Views: 6373

Rating: 4.3 / 5 (54 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Jeremiah Abshire

Birthday: 1993-09-14

Address: Apt. 425 92748 Jannie Centers, Port Nikitaville, VT 82110

Phone: +8096210939894

Job: Lead Healthcare Manager

Hobby: Watching movies, Watching movies, Knapping, LARPing, Coffee roasting, Lacemaking, Gaming

Introduction: My name is Jeremiah Abshire, I am a outstanding, kind, clever, hilarious, curious, hilarious, outstanding person who loves writing and wants to share my knowledge and understanding with you.