Splunk: How to query InfluxDB
I love InfluxDB metrics DB, but i don’t like its alerts. I love Splunk query, so how can i query InfluxDB data to alert? i finally got this | makeresults | eval influx_token=”your-influx-token” | eval query=”SELECT last(*) FROM \”disk\” WHERE time>now()-15m group by host,*” | eval header=”{\”Authorization\”:\”Token “+influx_token+”\”}” | urlencode query | eval influx_url=”https://your-influx-server/query?db=telegraf&q=”+query | curl method=get urifield=influx_url headerfield=header | spath input=curl_message output=myfield path=results{} | fields myfield | spath input=myfield output=series path=series{} | fields – myfield | mvexpand series | spath input=series | fields – series | rename columns{} as columns,values{}{} as values , tags.* as * | search NOT path IN(“*boot*”,”*etc*”) | eval column_name=mvindex(columns,0)Read More →