1、cd /opt/splunk/etc/system/bin
cd /opt/splunk/bin/scripts/(默认目录)
vi 4444.sh
#!/bin/sh
/usr/bin/vmstat
chmod +x ./4444.sh
2. vi /opt/splunk/etc/system/local/inputs.conf
增加如下内容:
[script:///opt/splunk/etc/system/bin/4444.sh]
sourcetype= 333
interval= 30
3.重启Splunk服务,等30秒,搜索sourcetype=333
转载于:https://blog.51cto.com/wangxiangjie/1347090