Set up Ingest monitoring
This topic describes how to set up index monitoring.
Select indexes for monitoring
When you first install the app, you must select the indexes that you want to monitor.
You can choose to monitor all indexes, or, for better search performance and optimal resource use, select specific indexes for monitoring. You can always update this list later in the app settings.
-
In Ingest Monitoring app, select Settings, and click Edit next to the Monitoring configuration section.
-
Select indexes for monitoring:
-
To monitor all indexes, check Monitor all indexes.
-
To select indexes, from the Indexes to monitor to monitor drop-down, select all of the indexes you wish to monitor.
-
-
From the Latency detection window menu, select the search range for latency metrics. Each search includes a 24-hour buffer into the future to account for potential timestamp skew.
Note: A longer range improves detection of slow-arriving data but increases search runtime. -
From the Metrics collection frequency menu, select how often Splunk runs the scheduled searches that collect ingest metrics:
-
Every 5 minutes
-
Every 15 minutes
-
Every 30 minutes
Lower frequency reduces system load but delays metric updates.
-