1cd /opt/splunk/etc/system/bin

cd /opt/splunk/bin/scripts/(默认目录)


vi 4444.sh

#!/bin/sh

/usr/bin/vmstat

chmod +x ./4444.sh



2. vi /opt/splunk/etc/system/local/inputs.conf


增加如下内容:

[script:///opt/splunk/etc/system/bin/4444.sh]

sourcetype= 333

interval= 30



3.重启Splunk服务,等30秒,搜索sourcetype=333