<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Linux server - Splunk Forwarder - './splunk list monitor' in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Linux-server-Splunk-Forwarder-splunk-list-monitor/m-p/40673#M7546</link>
    <description>&lt;P&gt;My bad, had a special moment when I wrote this. Try the edited version&lt;/P&gt;</description>
    <pubDate>Mon, 26 Nov 2012 19:03:30 GMT</pubDate>
    <dc:creator>Drainy</dc:creator>
    <dc:date>2012-11-26T19:03:30Z</dc:date>
    <item>
      <title>Linux server - Splunk Forwarder - './splunk list monitor'</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Linux-server-Splunk-Forwarder-splunk-list-monitor/m-p/40670#M7543</link>
      <description>&lt;P&gt;When I login as Admin on one of my Splunk Forwarders (Linux, cmd line only) and issue the ./splunk list monitor command I see the list of monitors.  No problem there.  In which file are these monitors stored?  I've looked in etc/system/local/inputs and outputs.conf but they're not there.&lt;/P&gt;

&lt;P&gt;I also need to remove a couple of the monitors that display as we have moved the directories.&lt;/P&gt;

&lt;P&gt;Any ideas, suggestions would be appreciated.  I've already RTFM'd but didn't find the answer.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;

&lt;P&gt;Bill&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2012 20:03:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Linux-server-Splunk-Forwarder-splunk-list-monitor/m-p/40670#M7543</guid>
      <dc:creator>wbcattell</dc:creator>
      <dc:date>2012-11-20T20:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: Linux server - Splunk Forwarder - './splunk list monitor'</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Linux-server-Splunk-Forwarder-splunk-list-monitor/m-p/40671#M7544</link>
      <description>&lt;P&gt;try &lt;CODE&gt;./splunk cmd btool inputs list --debug&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;This will produce a list of all stanzas and before each line will be the name of the app it is defined within to help you track those pesky hobbit... configs down&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2012 20:20:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Linux-server-Splunk-Forwarder-splunk-list-monitor/m-p/40671#M7544</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-11-20T20:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: Linux server - Splunk Forwarder - './splunk list monitor'</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Linux-server-Splunk-Forwarder-splunk-list-monitor/m-p/40672#M7545</link>
      <description>&lt;P&gt;Thanks for the input.  Tried that - came up with "invalid command:  inputs".&lt;/P&gt;

&lt;P&gt;I'm running forwarder version 4.3.4&lt;/P&gt;</description>
      <pubDate>Mon, 26 Nov 2012 15:27:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Linux-server-Splunk-Forwarder-splunk-list-monitor/m-p/40672#M7545</guid>
      <dc:creator>wbcattell</dc:creator>
      <dc:date>2012-11-26T15:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: Linux server - Splunk Forwarder - './splunk list monitor'</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Linux-server-Splunk-Forwarder-splunk-list-monitor/m-p/40673#M7546</link>
      <description>&lt;P&gt;My bad, had a special moment when I wrote this. Try the edited version&lt;/P&gt;</description>
      <pubDate>Mon, 26 Nov 2012 19:03:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Linux-server-Splunk-Forwarder-splunk-list-monitor/m-p/40673#M7546</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-11-26T19:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: Linux server - Splunk Forwarder - './splunk list monitor'</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Linux-server-Splunk-Forwarder-splunk-list-monitor/m-p/40674#M7547</link>
      <description>&lt;P&gt;Also, the &lt;CODE&gt;./splunk list monitor&lt;/CODE&gt; command lists the individual files that are being monitored. The &lt;CODE&gt;inputs.conf&lt;/CODE&gt; tells you the directories and files that were explicitly specificed, but it won't list the individual file names.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Nov 2012 19:24:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Linux-server-Splunk-Forwarder-splunk-list-monitor/m-p/40674#M7547</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2012-11-26T19:24:44Z</dc:date>
    </item>
  </channel>
</rss>

