<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure inputs.conf on a universal forwarder to ignore monitoring and indexing folders that are older than 1 day? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-inputs-conf-on-a-universal-forwarder-to-ignore/m-p/274507#M52660</link>
    <description>&lt;P&gt;I believe "ignoreOlderThan" will only ignore files. My problem is splunk is taking too much time in traversing through the folders to find a match. &lt;/P&gt;</description>
    <pubDate>Mon, 08 Feb 2016 18:15:07 GMT</pubDate>
    <dc:creator>vaibhavagg2006</dc:creator>
    <dc:date>2016-02-08T18:15:07Z</dc:date>
    <item>
      <title>How to configure inputs.conf on a universal forwarder to ignore monitoring and indexing folders that are older than 1 day?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-inputs-conf-on-a-universal-forwarder-to-ignore/m-p/274505#M52658</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;I am monitoring a folder which has high level of nesting and daily, 1000's of folders gets created. The name of the folder is unique based on some id. I am seeing a delay of 10-12 hours in getting the logs which are placed deep in the nth folder. I believe this is because Splunk checks for each and every folder sequentially for a match. Can we ignore folders older than 1 day so that Splunk does not search inside old folders? I am using a universal forwarder with good bunch of indexers to index the data. There is no throughput issue. The daily ingestion is around 1-2 gigs.&lt;BR /&gt;
Below is my inputs.conf stanza&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///&amp;lt;folder path&amp;gt;]
_TCP_ROUTING = prod
ignoreOlderThan = 2d
whitelist = .log
index = index1
sourcetype = sample_sourcetype
disabled = 0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Please provide your inputs on this issue.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2016 23:37:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-inputs-conf-on-a-universal-forwarder-to-ignore/m-p/274505#M52658</guid>
      <dc:creator>vaibhavagg2006</dc:creator>
      <dc:date>2016-02-05T23:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure inputs.conf on a universal forwarder to ignore monitoring and indexing folders that are older than 1 day?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-inputs-conf-on-a-universal-forwarder-to-ignore/m-p/274506#M52659</link>
      <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.3/Data/Monitorfilesanddirectorieswithinputs.conf"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.3/Data/Monitorfilesanddirectorieswithinputs.conf&lt;/A&gt; covers it.&lt;BR /&gt;
ignoreOlderThan = 2d seems to be the right set-up.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Feb 2016 01:19:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-inputs-conf-on-a-universal-forwarder-to-ignore/m-p/274506#M52659</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-02-06T01:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure inputs.conf on a universal forwarder to ignore monitoring and indexing folders that are older than 1 day?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-inputs-conf-on-a-universal-forwarder-to-ignore/m-p/274507#M52660</link>
      <description>&lt;P&gt;I believe "ignoreOlderThan" will only ignore files. My problem is splunk is taking too much time in traversing through the folders to find a match. &lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2016 18:15:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-inputs-conf-on-a-universal-forwarder-to-ignore/m-p/274507#M52660</guid>
      <dc:creator>vaibhavagg2006</dc:creator>
      <dc:date>2016-02-08T18:15:07Z</dc:date>
    </item>
  </channel>
</rss>

