Integrating CEM/Introscope with Splunk

Question asked by jcutting on May 2, 2012
Latest reply on Dec 13, 2013 by sbsbb
There was an earlier thread about integrating Splunk with APM, but it mainly focused around pulling introscope application logs into Splunk. What I'm referring to is either

1) Pulling data from CEM/Introscope into Splunk. For example, taking CEM transaction data or defect data and adding it to Splunk.


2) Adding custom metrics to Introscope based on Splunk searches (similar to what people might do with an epagent watching a log file). One example might be to add a metric for number of errors in a log per interval, but based upon a splunk search.

Has anyone done anything like this? I'm particularly interested in getting at the CEM data-- I'd like to be able to get a feed of transactions by user, ip, response time, status, etc.