<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I monitor a file through REST api in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-monitor-a-file-through-REST-api/m-p/357825#M5345</link>
    <description>&lt;P&gt;Hi @wava11,&lt;BR /&gt;
 There are two ways to do this. I prefer first because if you are beginner with RestApi and Splunk it will help you a lot to understand configuration file in general.&lt;/P&gt;

&lt;P&gt;1st.&lt;BR /&gt;
I hope you understand configuration files in splunk. There is a configuration file for storing input - inputs.conf. Adding stanza in it will add file to monitor. Learn how to write stanza in inputs.conf file &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.2/Admin/Inputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.2/Admin/Inputsconf&lt;/A&gt;. Now there is a way in RestApi via which you can edit any configuration file in splunk - &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.2/RESTTUT/RESTconfigurations"&gt;https://docs.splunk.com/Documentation/Splunk/7.0.2/RESTTUT/RESTconfigurations&lt;/A&gt;. Now you know the stanza add it via RestApi.&lt;/P&gt;

&lt;P&gt;Restart the splunk and you are done.&lt;BR /&gt;
(You can also restart Splunk with RestApi - https://[Host]:[Port]/services/server/control/restart)&lt;/P&gt;

&lt;P&gt;2nd.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.2/RESTREF/RESTinput"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.2/RESTREF/RESTinput&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
@vatsaljagani&lt;/P&gt;</description>
    <pubDate>Sun, 18 Mar 2018 11:38:19 GMT</pubDate>
    <dc:creator>VatsalJagani</dc:creator>
    <dc:date>2018-03-18T11:38:19Z</dc:date>
    <item>
      <title>How do I monitor a file through REST api</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-monitor-a-file-through-REST-api/m-p/357824#M5344</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm new to splunk and will be working with its REST api.&lt;BR /&gt;
So far I've been adding files to be monitored using splunk's UI, but now i need to do so using its REST api.&lt;BR /&gt;
Is it possible ? &lt;BR /&gt;
If so how can it be done ?&lt;/P&gt;</description>
      <pubDate>Sat, 17 Mar 2018 17:49:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-monitor-a-file-through-REST-api/m-p/357824#M5344</guid>
      <dc:creator>wava11</dc:creator>
      <dc:date>2018-03-17T17:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: How do I monitor a file through REST api</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-monitor-a-file-through-REST-api/m-p/357825#M5345</link>
      <description>&lt;P&gt;Hi @wava11,&lt;BR /&gt;
 There are two ways to do this. I prefer first because if you are beginner with RestApi and Splunk it will help you a lot to understand configuration file in general.&lt;/P&gt;

&lt;P&gt;1st.&lt;BR /&gt;
I hope you understand configuration files in splunk. There is a configuration file for storing input - inputs.conf. Adding stanza in it will add file to monitor. Learn how to write stanza in inputs.conf file &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.2/Admin/Inputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.2/Admin/Inputsconf&lt;/A&gt;. Now there is a way in RestApi via which you can edit any configuration file in splunk - &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.2/RESTTUT/RESTconfigurations"&gt;https://docs.splunk.com/Documentation/Splunk/7.0.2/RESTTUT/RESTconfigurations&lt;/A&gt;. Now you know the stanza add it via RestApi.&lt;/P&gt;

&lt;P&gt;Restart the splunk and you are done.&lt;BR /&gt;
(You can also restart Splunk with RestApi - https://[Host]:[Port]/services/server/control/restart)&lt;/P&gt;

&lt;P&gt;2nd.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.2/RESTREF/RESTinput"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.2/RESTREF/RESTinput&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
@vatsaljagani&lt;/P&gt;</description>
      <pubDate>Sun, 18 Mar 2018 11:38:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-do-I-monitor-a-file-through-REST-api/m-p/357825#M5345</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2018-03-18T11:38:19Z</dc:date>
    </item>
  </channel>
</rss>

