You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@camel.apache.org by ac...@apache.org on 2016/06/07 09:07:03 UTC

[2/2] camel git commit: Added camel-splunk docs to Gitbook

Added camel-splunk docs to Gitbook


Project: http://git-wip-us.apache.org/repos/asf/camel/repo
Commit: http://git-wip-us.apache.org/repos/asf/camel/commit/b227c607
Tree: http://git-wip-us.apache.org/repos/asf/camel/tree/b227c607
Diff: http://git-wip-us.apache.org/repos/asf/camel/diff/b227c607

Branch: refs/heads/master
Commit: b227c607c14db33abe3edf154d89199662754c8e
Parents: df5a8e0
Author: Andrea Cosentino <an...@gmail.com>
Authored: Tue Jun 7 11:05:23 2016 +0200
Committer: Andrea Cosentino <an...@gmail.com>
Committed: Tue Jun 7 11:05:23 2016 +0200

----------------------------------------------------------------------
 .../camel-splunk/src/main/docs/splunk.adoc      | 249 +++++++++++++++++++
 docs/user-manual/en/SUMMARY.md                  |   1 +
 2 files changed, 250 insertions(+)
----------------------------------------------------------------------


http://git-wip-us.apache.org/repos/asf/camel/blob/b227c607/components/camel-splunk/src/main/docs/splunk.adoc
----------------------------------------------------------------------
diff --git a/components/camel-splunk/src/main/docs/splunk.adoc b/components/camel-splunk/src/main/docs/splunk.adoc
new file mode 100644
index 0000000..1e63732
--- /dev/null
+++ b/components/camel-splunk/src/main/docs/splunk.adoc
@@ -0,0 +1,249 @@
+[[Splunk-SplunkComponent]]
+Splunk Component
+~~~~~~~~~~~~~~~~
+
+*Available as of Camel 2.13*
+
+The Splunk component provides access to
+http://docs.splunk.com/Documentation/Splunk/latest[Splunk] using the
+Splunk provided https://github.com/splunk/splunk-sdk-java[client] api,
+and it enables you to publish and search for events in Splunk.
+
+Maven users will need to add the following dependency to their pom.xml
+for this component:
+
+[source,xml]
+---------------------------------------------
+ <dependency>
+        <groupId>org.apache.camel</groupId>
+        <artifactId>camel-splunk</artifactId>
+        <version>${camel-version}</version>
+    </dependency>
+---------------------------------------------
+
+[[Splunk-URIformat]]
+URI format
+^^^^^^^^^^
+
+[source,java]
+-------------------------------
+  splunk://[endpoint]?[options]
+-------------------------------
+
+[[Splunk-ProducerEndpoints:]]
+Producer Endpoints:
+^^^^^^^^^^^^^^^^^^^
+
+[width="100%",cols="10%,90%",options="header",]
+|=======================================================================
+|Endpoint |Description
+
+|stream |Streams data to a named index or the default if not specified.
+When using stream mode be aware of that Splunk has some internal buffer
+(about 1MB or so) before events gets to the index. 
+If you need realtime, better use submit or tcp mode.
+
+|submit |submit mode. Uses Splunk rest api to publish events to a named index or
+the default if not specified.
+
+|tcp |tcp mode. Streams data to a tcp port, and requires a open receiver port
+in Splunk.
+|=======================================================================
+
+When publishing events the message body should contain a
+SplunkEvent.��See comment under message body.
+
+*Example*
+
+[source,java]
+----------------------------------------------------------------------------------------------------------------------
+      from("direct:start").convertBodyTo(SplunkEvent.class)
+          .to("splunk://submit?username=user&password=123&index=myindex&sourceType=someSourceType&source=mySource")...
+----------------------------------------------------------------------------------------------------------------------
+
+In this example a converter is required to convert to a SplunkEvent
+class.
+
+[[Splunk-ConsumerEndpoints:]]
+Consumer Endpoints:
+^^^^^^^^^^^^^^^^^^^
+
+[width="100%",cols="10%,90%",options="header",]
+|=======================================================================
+|Endpoint |Description
+
+|normal |Performs normal search and requires a search query in the search option.
+
+|savedsearch |Performs search based on a search query saved in splunk and requires the
+name of the query in the savedSearch option.
+|=======================================================================
+
+*Example*
+
+[source,java]
+---------------------------------------------------------------------------------------------------------------------------------------------
+      from("splunk://normal?delay=5s&username=user&password=123&initEarliestTime=-10s&search=search index=myindex sourcetype=someSourcetype")
+          .to("direct:search-result");
+---------------------------------------------------------------------------------------------------------------------------------------------
+
+camel-splunk creates a route exchange per search result with a
+SplunkEvent in the body.
+
+[[Splunk-URIOptions]]
+URI Options
+^^^^^^^^^^^
+
+
+// component options: START
+The Splunk component supports 1 options which are listed below.
+
+
+
+{% raw %}
+[width="100%",cols="2s,1m,8",options="header"]
+|=======================================================================
+| Name | Java Type | Description
+| splunkConfigurationFactory | SplunkConfigurationFactory | To use the SplunkConfigurationFactory
+|=======================================================================
+{% endraw %}
+// component options: END
+
+
+
+// endpoint options: START
+The Splunk component supports 43 endpoint options which are listed below:
+
+{% raw %}
+[width="100%",cols="2s,1,1m,1m,5",options="header"]
+|=======================================================================
+| Name | Group | Default | Java Type | Description
+| name | common |  | String | *Required* Name has no purpose
+| app | common |  | String | Splunk app
+| connectionTimeout | common | 5000 | int | Timeout in MS when connecting to Splunk server
+| host | common | localhost | String | Splunk host.
+| owner | common |  | String | Splunk owner
+| password | common |  | String | Password for Splunk
+| port | common | 8089 | int | Splunk port
+| scheme | common | https | String | Splunk scheme
+| sslProtocol | common | TLSv1.2 | SSLSecurityProtocol | Set the ssl protocol to use
+| username | common |  | String | Username for Splunk
+| useSunHttpsHandler | common | false | boolean | Use sun.net.www.protocol.https.Handler Https handler to establish the Splunk Connection. Can be useful when running in application servers to avoid app. server https handling.
+| bridgeErrorHandler | consumer | false | boolean | Allows for bridging the consumer to the Camel routing Error Handler which mean any exceptions occurred while the consumer is trying to pickup incoming messages or the likes will now be processed as a message and handled by the routing Error Handler. By default the consumer will use the org.apache.camel.spi.ExceptionHandler to deal with exceptions that will be logged at WARN/ERROR level and ignored.
+| count | consumer |  | int | A number that indicates the maximum number of entities to return.
+| earliestTime | consumer |  | String | Earliest time of the search time window.
+| initEarliestTime | consumer |  | String | Initial start offset of the first search
+| latestTime | consumer |  | String | Latest time of the search time window.
+| savedSearch | consumer |  | String | The name of the query saved in Splunk to run
+| search | consumer |  | String | The Splunk query to run
+| sendEmptyMessageWhenIdle | consumer | false | boolean | If the polling consumer did not poll any files you can enable this option to send an empty message (no body) instead.
+| streaming | consumer |  | Boolean | Sets streaming mode. Streaming mode sends exchanges as they are received rather than in a batch.
+| exceptionHandler | consumer (advanced) |  | ExceptionHandler | To let the consumer use a custom ExceptionHandler. Notice if the option bridgeErrorHandler is enabled then this options is not in use. By default the consumer will deal with exceptions that will be logged at WARN/ERROR level and ignored.
+| pollStrategy | consumer (advanced) |  | PollingConsumerPollStrategy | A pluggable org.apache.camel.PollingConsumerPollingStrategy allowing you to provide your custom implementation to control error handling usually occurred during the poll operation before an Exchange have been created and being routed in Camel.
+| eventHost | producer |  | String | Override the default Splunk event host field
+| index | producer |  | String | Splunk index to write to
+| raw | producer | false | boolean | Should the payload be inserted raw
+| source | producer |  | String | Splunk source argument
+| sourceType | producer |  | String | Splunk sourcetype argument
+| tcpReceiverPort | producer |  | int | Splunk tcp receiver port
+| exchangePattern | advanced | InOnly | ExchangePattern | Sets the default exchange pattern when creating an exchange
+| synchronous | advanced | false | boolean | Sets whether synchronous processing should be strictly used or Camel is allowed to use asynchronous processing (if supported).
+| backoffErrorThreshold | scheduler |  | int | The number of subsequent error polls (failed due some error) that should happen before the backoffMultipler should kick-in.
+| backoffIdleThreshold | scheduler |  | int | The number of subsequent idle polls that should happen before the backoffMultipler should kick-in.
+| backoffMultiplier | scheduler |  | int | To let the scheduled polling consumer backoff if there has been a number of subsequent idles/errors in a row. The multiplier is then the number of polls that will be skipped before the next actual attempt is happening again. When this option is in use then backoffIdleThreshold and/or backoffErrorThreshold must also be configured.
+| delay | scheduler | 500 | long | Milliseconds before the next poll. You can also specify time values using units such as 60s (60 seconds) 5m30s (5 minutes and 30 seconds) and 1h (1 hour).
+| greedy | scheduler | false | boolean | If greedy is enabled then the ScheduledPollConsumer will run immediately again if the previous run polled 1 or more messages.
+| initialDelay | scheduler | 1000 | long | Milliseconds before the first poll starts. You can also specify time values using units such as 60s (60 seconds) 5m30s (5 minutes and 30 seconds) and 1h (1 hour).
+| runLoggingLevel | scheduler | TRACE | LoggingLevel | The consumer logs a start/complete log line when it polls. This option allows you to configure the logging level for that.
+| scheduledExecutorService | scheduler |  | ScheduledExecutorService | Allows for configuring a custom/shared thread pool to use for the consumer. By default each consumer has its own single threaded thread pool.
+| scheduler | scheduler | none | ScheduledPollConsumerScheduler | To use a cron scheduler from either camel-spring or camel-quartz2 component
+| schedulerProperties | scheduler |  | Map | To configure additional properties when using a custom scheduler or any of the Quartz2 Spring based scheduler.
+| startScheduler | scheduler | true | boolean | Whether the scheduler should be auto started.
+| timeUnit | scheduler | MILLISECONDS | TimeUnit | Time unit for initialDelay and delay options.
+| useFixedDelay | scheduler | true | boolean | Controls if fixed delay or fixed rate is used. See ScheduledExecutorService in JDK for details.
+|=======================================================================
+{% endraw %}
+// endpoint options: END
+
+
+[[Splunk-Messagebody]]
+Message body
+^^^^^^^^^^^^
+
+Splunk operates on data in key/value pairs. The SplunkEvent class is a
+placeholder for such data, and should be in the message body for the producer. 
+Likewise it will be returned in the body per search
+result for the consumer.
+
+As of Camel 2.16.0 you can send raw data to Splunk by setting the raw
+option on the producer endpoint. This is useful for eg. json/xml and
+other payloads where Splunk has build in support.�
+
+[[Splunk-UseCases]]
+Use Cases
+^^^^^^^^^
+
+Search Twitter for tweets with music and publish events to Splunk
+
+[source,java]
+--------------------------------------------------------------------------------------------------------------------------------------------
+      from("twitter://search?type=polling&keywords=music&delay=10&consumerKey=abc&consumerSecret=def&accessToken=hij&accessTokenSecret=xxx")
+          .convertBodyTo(SplunkEvent.class)
+          .to("splunk://submit?username=foo&password=bar&index=camel-tweets&sourceType=twitter&source=music-tweets");
+--------------------------------------------------------------------------------------------------------------------------------------------
+
+To convert a Tweet to a SplunkEvent you could use a converter like
+
+[source,java]
+----------------------------------------------------------------------------------
+@Converter
+public class Tweet2SplunkEvent {
+    @Converter
+    public static SplunkEvent convertTweet(Status status) {
+        SplunkEvent data = new SplunkEvent("twitter-message", null);
+        //data.addPair("source", status.getSource());
+        data.addPair("from_user", status.getUser().getScreenName());
+        data.addPair("in_reply_to", status.getInReplyToScreenName());
+        data.addPair(SplunkEvent.COMMON_START_TIME, status.getCreatedAt());
+        data.addPair(SplunkEvent.COMMON_EVENT_ID, status.getId());
+        data.addPair("text", status.getText());
+        data.addPair("retweet_count", status.getRetweetCount());
+        if (status.getPlace() != null) {
+            data.addPair("place_country", status.getPlace().getCountry());
+            data.addPair("place_name", status.getPlace().getName());
+            data.addPair("place_street", status.getPlace().getStreetAddress());
+        }
+        if (status.getGeoLocation() != null) {
+            data.addPair("geo_latitude", status.getGeoLocation().getLatitude());
+            data.addPair("geo_longitude", status.getGeoLocation().getLongitude());
+        }
+        return data;
+    }
+}
+----------------------------------------------------------------------------------
+
+Search Splunk for tweets
+
+[source,java]
+--------------------------------------------------------------------------------------------------------------------------------
+      from("splunk://normal?username=foo&password=bar&initEarliestTime=-2m&search=search index=camel-tweets sourcetype=twitter")
+          .log("${body}");
+--------------------------------------------------------------------------------------------------------------------------------
+
+[[Splunk-Othercomments]]
+Other comments
+^^^^^^^^^^^^^^
+
+Splunk comes with a variety of options for leveraging machine generated
+data with prebuilt apps for analyzing and displaying this.  +
+ For example the jmx app. could be used to publish jmx attributes, eg.
+route and jvm metrics to Splunk, and displaying this on a dashboard.
+
+[[Splunk-SeeAlso]]
+See Also
+^^^^^^^^
+
+* link:configuring-camel.html[Configuring Camel]
+* link:component.html[Component]
+* link:endpoint.html[Endpoint]
+* link:getting-started.html[Getting Started]
+

http://git-wip-us.apache.org/repos/asf/camel/blob/b227c607/docs/user-manual/en/SUMMARY.md
----------------------------------------------------------------------
diff --git a/docs/user-manual/en/SUMMARY.md b/docs/user-manual/en/SUMMARY.md
index dd955d4..c618156 100644
--- a/docs/user-manual/en/SUMMARY.md
+++ b/docs/user-manual/en/SUMMARY.md
@@ -244,6 +244,7 @@
     * [Solr](solr.adoc)
     * [Spark](spark.adoc)
     * [Spark-Rest](spark-rest.adoc)
+    * [Splunk](splunk.adoc)
     * [Telegram](telegram.adoc)
     * [Twitter](twitter.adoc)
     * [Websocket](websocket.adoc)