Your user has permission to search the index you specified for your data from Kepware.If you do not see data, check that the following are true: | mstats avg(_value) as Value WHERE index= metric_name=* by metric_name asset To test that data ingestion is working, go to your search head and run this search: Verify that your data is coming in as expected
#QUICKSAND VISUALS VIDEOS HOW TO#
If you created separate input stanzas to send data to different indexes, create an IDF for Splunk connection for each input stanza, matching the port in the connection to the port that you configured in the input stanza.įor instructions on how to configure Kepware IDF, go to the Kepware website and search for "Industrial Data Forwarder for Splunk manual". If you want to divide data into separate indexes, set up a unique TCP input stanza for each index, each listening on a different port.Ĭonfigure the IDF to send data to your Splunk universal forwarderĬonfigure the Kepware IDF to forward the data you want to send to the TCP port you specified for the input. Write an input stanza using the following template:.Create a new nf file in %SPLUNK_HOME%\etc\apps\TA-kepware-to-metrics\local.
#QUICKSAND VISUALS VIDEOS INSTALL#
In a distributed environment, install this add-on to the universal forwarder you plan to use to collect your Kepware data, your indexers, and your search heads.įor step-by-step installation instructions, see Install an add-on in a distributed Splunk Enterprise deployment.Ĭonfigure a Splunk universal forwarder to collect data from Kepware This add-on applies parsing and index-time transformations to your data to prepare it for use in Splunk IAI. Install the Kepware IDF to Metrics Index Add-on for Splunkĭownload the Kepware IDF to Metrics Index Add-on for Splunk from Splunkbase.
At least one index configured to store the metrics data you receive from Kepware.A KEPServerEX with the Industrial Data Forwarder for Splunk plug-in installed.
If you have this plug-in, you can use it to send your data to a Splunk forwarder listening on a TCP port, and then apply the Kepware IDF to Metrics Index Add-on for Splunk to prepare your data for use in Splunk Industrial Asset Intelligence. Kepware's Industrial Data Forwarder (IDF) for Splunk streams real-time data from KEPServerEX into the Splunk platform over TCP. Configure the Kepware IDF for Splunk to send data to Splunk IAI