Inputs

The app provides three input types for data collection:

  • Tests Stream: Collects test metrics data via ThousandEyes OpenTelemetry (OTel) streams and Path Visualization data via the ThousandEyes API.

  • Event: Collects events detected on the Cisco ThousandEyes platform via the API.

  • Activity: Collects activity log events from the Cisco ThousandEyes platform via the API.

Prerequisites for Tests Stream Input

  • HTTP Event Collector (HEC) must be enabled.

  • SSL must be enabled for HEC.

  • At least one HEC token should be configured and enabled.

Enable HTTP Event Collector and SSL

  • Splunk Cloud: HEC and SSL are enabled by default.

  • Splunk Enterprise:

    1. Navigate to Settings > Data inputs > HTTP Event Collector.

    2. Click Global settings.

    3. Enable All Tokens.

    4. Check Enable SSL (if not already enabled).

Note: Ensure the Splunk HEC certificates are valid and not self-signed.

Configure the HTTP Event Collector Token

  1. Navigate to Settings > Data inputs > HTTP Event Collector.

  2. Click New Token.

  3. Provide a Name and configure optional settings as needed. Click Next.

  4. Select Allowed Indexes and update the Default Index if required.

  5. Click Review and then Submit.

Enable the HTTP Event Collector Token

  1. Navigate to Settings > Data inputs > HTTP Event Collector.

  2. In the Actions column, click Enable for the token if it is not already active.

Add an Input

  1. Navigate to Cisco ThousandEyes App for Splunk > Inputs.

  2. Click Create New Input.

  3. Select the input type from the dropdown menu.

  4. Fill in the required parameters for the selected input configuration.

  5. Click Add Input.

Input Parameters

Tests Stream Input

Parameter

Type

Required?

Description

Name

Textbox

Yes

Unique name for the input

ThousandEyes User

Dropdown

Yes

Select a user created in ThousandEyes User configuration

Account Group

Dropdown

Yes

Account group for data collection

CEA Tests

Multi-valued Dropdown

No

Select CEA Tests for metrics collection

Endpoint Tests

Multi-valued Dropdown

No

Select Endpoint Tests for metrics collection

HEC Token

Dropdown

Yes

Splunk HEC token for stream data

Test Index

Dropdown

Yes

Index for test metric data

Include Path Information

Checkbox

No

Check to collect Path Visualization data

Path Index

Dropdown

Yes (if Path Information is enabled)

Index for Path Visualization data

Path Interval

Textbox

Yes (if Path Information is enabled)

Fetch interval for Path Visualization data

Event Input

Parameter

Type

Required?

Description

Name

Textbox

Yes

Unique name for the input

ThousandEyes User

Dropdown

Yes

Select a user created in ThousandEyes User configuration

Account Group

Dropdown

Yes

Account group for data collection

Index

Dropdown

Yes

Index for event data

Interval

Dropdown

Yes

Fetch interval for event data

Activity Input

Parameter

Type

Required?

Description

Name

Textbox

Yes

Unique name for the input

ThousandEyes User

Dropdown

Yes

Select a user created in ThousandEyes User configuration

Account Group

Dropdown

Yes

Account group or "All" for data collection

Index

Dropdown

Yes

Index for activity data

Interval

Dropdown

Yes

Fetch interval for activity data

Manage Inputs

Disable an Input

  1. Navigate to Cisco ThousandEyes App for Splunk > Inputs.

  2. Locate the input in the list.

  3. Click Disable in the Actions column.

Enable an Input

  1. Navigate to Cisco ThousandEyes App for Splunk > Inputs.

  2. Locate the input in the list.

  3. Click Enable in the Actions column.

Edit an Input

  1. Navigate to Cisco ThousandEyes App for Splunk > Inputs.

  2. Locate the input in the list you want to edit.

  3. In the Actions column, click Edit.

  4. Update the desired fields.

  5. Click Update.

Clone an Input

  1. Navigate to Cisco ThousandEyes App for Splunk > Inputs.

  2. Locate the input in the list you want to clone.

  3. In the Actions column, click Clone.

  4. Update the desired fields.

  5. Click Save.

Delete an Input

  1. Navigate to Cisco ThousandEyes App for Splunk > Inputs.

  2. Locate the input in the list you want to delete.

  3. In the Actions column, click Delete.

  4. Confirm the deletion in the pop-up window.

Last updated