Searching OverOps data within Splunk
It might be useful to stream data from OverOps into Splunk for additional search, data discovery, visualizations and advanced analytics.
This can be achieved by utilizing the OverOps publish metrics capability, and can be configured by going to the OverOps settings menu. (Settings -> Publish Metrics)
But first, the Splunk environment will need to have the proper data input established to accept statsD data. See Splunk documentation to create the data input: https://docs.splunk.com/Documentation/Splunk/7.1.0/Metrics/GetMetricsInStatsd
Note the Splunk data input in this use case should be defined as the following:
- Port: UDP
- Source Type: Metrics -> StatsD
- App Context: Search & Reporting
- Index Type: Events
Now we can configure OverOps to publish metrics to the Splunk data input.
- From the OverOps UI, go to Settings -> Publish Metrics
- Turn the toggle on for StatsD
- For the server address, enter the <splunk server>:<splunk udp port number>
- Specify the metric formats.
The formats above are recommended for Splunk to easily extract the fields via the Splunk regular expression extraction method. See Splunk documentation to extract fields with regular expressions: http://docs.splunk.com/Documentation/Splunk/7.1.0/Knowledge/ExtractfieldsinteractivelywithIFX