<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Analyzing Splunk Internal Logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Analyzing-Splunk-Internal-Logs-What-is-Tailing-Processor-and/m-p/635917#M108790</link>
    <description>&lt;P&gt;These two components help with the handling of &lt;FONT face="courier new,courier"&gt;monitor://&lt;/FONT&gt; inputs.&amp;nbsp; &lt;FONT face="courier new,courier"&gt;WatchedFile&lt;/FONT&gt; detects when the file changes and &lt;FONT face="courier new,courier"&gt;TailingProcessor&lt;/FONT&gt; reads the new data.&amp;nbsp; The first message says the component will detect changes using the file modification time.&amp;nbsp; The second message says it's asked &lt;FONT face="courier new,courier"&gt;WatchedFile&lt;/FONT&gt; to keep an eye on the specified file path.&lt;/P&gt;</description>
    <pubDate>Fri, 24 Mar 2023 12:44:28 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2023-03-24T12:44:28Z</dc:date>
    <item>
      <title>Analyzing Splunk Internal Logs- What is Tailing Processor and Watch file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Analyzing-Splunk-Internal-Logs-What-is-Tailing-Processor-and/m-p/635904#M108786</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I recently observed the splunk internal logs and found that there is a field component and found two values for component field -&lt;/P&gt;
&lt;P&gt;1&lt;STRONG&gt;.&lt;A href="https://es-starsiem.splunkcloud.com/en-US/app/search/search?q=search%20index%3D_internal%20%2Fvar%2Flib%2Fdocker%2Fcontainers%20%20NOT%20StreamedSearch&amp;amp;earliest=-7d%40h&amp;amp;latest=now&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;display.prefs.fieldFilter=src_&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22sourcetype%22%2C%22index%22%2C%22severity%22%2C%22event.Technique%22%2C%22EventID%22%2C%22direction%22%2C%22destinationPort%22%2C%22sourcePort%22%2C%22transport%22%2C%22service%22%2C%22message%22%2C%22user%22%2C%22userIdentity.arn%22%2C%22source_type%22%2C%22signature%22%2C%22LogonError%22%2C%22status_label%22%2C%22Total_Mb%22%2C%22fsize%22%2C%22total%22%2C%22Total1%22%2C%22userPrincipalName%22%2C%22ErrorNumber%22%2C%22dest_ip%22%2C%22file_size%22%2C%22eventName%22%2C%22Source_Workstation%22%2C%22WorkstationName%22%2C%22Workstation%22%2C%22dest%22%2C%22resources%7B%7D.ARN%22%2C%22httpRequest.uri%22%2C%22httpRequest.args%22%2C%22httpRequest.httpMethod%22%2C%22httpRequest.clientIp%22%2C%22userIdentity.principalId%22%2C%22httpRequest.headers%7B%7D.name%22%2C%22httpRequest.headers%7B%7D.value%22%2C%22file_hash%22%2C%22event.PatternDispositionDescription%22%2C%22event_desc%22%2C%22rule_name%22%2C%22notable_xref_id%22%2C%22errorMessage%22%2C%22status%22%2C%22event.PatternDispositionFlags.QuarantineFile%22%2C%22subject%22%2C%22event.LocalIP%22%2C%22event.UserName%22%2C%22src_user%22%2C%22file_name%22%2C%22SubjectUserName%22%2C%22TargetUserName%22%2C%22Target_User_Name%22%2C%22comment%22%2C%22Host%22%2C%22httpRequest.country%22%2C%22Website%22%2C%22ClientIp%22%2C%22eventSource%22%2C%22action%22%2C%22user_type%22%2C%22errorCode%22%2C%22Region%22%2C%22requestParameters.userName%22%2C%22IamUser%22%2C%22RequestUsername%22%2C%22webaclId%22%2C%22acl%22%2C%22userIdentity.userName%22%2C%22disposition_label%22%2C%22source_ip%22%2C%22src%22%2C%22dst%22%2C%22ServerIPAddress%22%2C%22Hash%22%2C%22md5%22%2C%22sha2%22%2C%22file_hash2%22%2C%22parent_file_sha2%22%2C%22Risk%20name%22%2C%22file_path%22%2C%22true_file_path%22%2C%22dmac%22%2C%22RequestUID%22%2C%22Requestid%22%2C%22Computer_Name%22%2C%22Computer_dest%22%2C%22event.ComputerName%22%2C%22Host_Name%22%2C%22ip%22%5D&amp;amp;sid=1679657469.108697#" target="_blank" rel="noopener"&gt;TailingProcesso&lt;/A&gt;r&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;2.Watched file&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;INFO&lt;/SPAN&gt; &lt;SPAN class=""&gt;WatchedFile&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;3338437&lt;/SPAN&gt; &lt;SPAN class=""&gt;tailreader0&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;Will&lt;/SPAN&gt; &lt;SPAN class=""&gt;use&lt;/SPAN&gt; &lt;SPAN class=""&gt;tracking&lt;/SPAN&gt; &lt;SPAN class=""&gt;rule=modtime&lt;/SPAN&gt; &lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;file=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;/path/.conf&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;INFO TailingProcessor&lt;SPAN&gt; [&lt;/SPAN&gt;3338433 MainTailingThread&lt;SPAN&gt;] &lt;/SPAN&gt;- Adding watch on path: /path&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Please help me understand what these logs says about.&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 19:41:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Analyzing-Splunk-Internal-Logs-What-is-Tailing-Processor-and/m-p/635904#M108786</guid>
      <dc:creator>umesh</dc:creator>
      <dc:date>2023-03-24T19:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: Analyzing Splunk Internal Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Analyzing-Splunk-Internal-Logs-What-is-Tailing-Processor-and/m-p/635917#M108790</link>
      <description>&lt;P&gt;These two components help with the handling of &lt;FONT face="courier new,courier"&gt;monitor://&lt;/FONT&gt; inputs.&amp;nbsp; &lt;FONT face="courier new,courier"&gt;WatchedFile&lt;/FONT&gt; detects when the file changes and &lt;FONT face="courier new,courier"&gt;TailingProcessor&lt;/FONT&gt; reads the new data.&amp;nbsp; The first message says the component will detect changes using the file modification time.&amp;nbsp; The second message says it's asked &lt;FONT face="courier new,courier"&gt;WatchedFile&lt;/FONT&gt; to keep an eye on the specified file path.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 12:44:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Analyzing-Splunk-Internal-Logs-What-is-Tailing-Processor-and/m-p/635917#M108790</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-03-24T12:44:28Z</dc:date>
    </item>
  </channel>
</rss>

