<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitor splunk file after restart in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-splunk-file-after-restart/m-p/377235#M5813</link>
    <description>&lt;P&gt;as per the document, during restart ,If the file or directory is not present on start, Splunk Enterprise checks for it every 24 hours from the time of the last restart. &lt;/P&gt;

&lt;P&gt;yes, as per the document file will be ignored until next check. not tested.&lt;/P&gt;

&lt;P&gt;if you are monitoring the existing directory, newly created file under this monitored directory will be monitored immediately.&lt;/P&gt;</description>
    <pubDate>Fri, 27 Jul 2018 12:39:20 GMT</pubDate>
    <dc:creator>thambisetty</dc:creator>
    <dc:date>2018-07-27T12:39:20Z</dc:date>
    <item>
      <title>Monitor splunk file after restart</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-splunk-file-after-restart/m-p/377234#M5812</link>
      <description>&lt;P&gt;On the Splunk docs it is given as &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;How Splunk Enterprise handles monitoring of files during restarts&lt;/STRONG&gt;&lt;BR /&gt;
When the Splunk server is restarted, it continues processing files where it left off. It first checks for the file or directory specified in a monitor configuration. If the file or directory is not present on start, Splunk Enterprise checks for it every 24 hours from the time of the last restart. The monitor process scans subdirectories of monitored directories continuously&lt;/P&gt;

&lt;P&gt;Suppose if I deployed inputs to monitor a file and restarted splunk after deploying and If the monitored file was not created yet. Does splunk enterprise check for that file only after 24 hours to reads the file. What if the file created after few minutes after restart. Will it be ignored until 24 hrs of restart.&lt;/P&gt;

&lt;P&gt;Suppose I gave wildcard for file name, Does it behave same. I can see newly created file was read by splunk immediately when it created for wild card file names.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2018 11:35:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-splunk-file-after-restart/m-p/377234#M5812</guid>
      <dc:creator>ankithreddy777</dc:creator>
      <dc:date>2018-07-27T11:35:27Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor splunk file after restart</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-splunk-file-after-restart/m-p/377235#M5813</link>
      <description>&lt;P&gt;as per the document, during restart ,If the file or directory is not present on start, Splunk Enterprise checks for it every 24 hours from the time of the last restart. &lt;/P&gt;

&lt;P&gt;yes, as per the document file will be ignored until next check. not tested.&lt;/P&gt;

&lt;P&gt;if you are monitoring the existing directory, newly created file under this monitored directory will be monitored immediately.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2018 12:39:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-splunk-file-after-restart/m-p/377235#M5813</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2018-07-27T12:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor splunk file after restart</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-splunk-file-after-restart/m-p/377236#M5814</link>
      <description>&lt;P&gt;How it works , if you use the wild card in file or directory name. such as&lt;/P&gt;

&lt;P&gt;[monitor.....././..../abc*&lt;/P&gt;

&lt;P&gt;Does the file with name "abcd"  which is created after few hours of restart  will be ignored until 24 hours? OR Is there any exception for this scenario? &lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2018 13:52:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-splunk-file-after-restart/m-p/377236#M5814</guid>
      <dc:creator>ankithreddy777</dc:creator>
      <dc:date>2018-07-27T13:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor splunk file after restart</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-splunk-file-after-restart/m-p/377237#M5815</link>
      <description>&lt;P&gt;if there is any exception in this scenario , that would be described in the doc. &lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2018 13:59:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-splunk-file-after-restart/m-p/377237#M5815</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2018-07-27T13:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor splunk file after restart</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-splunk-file-after-restart/m-p/377238#M5816</link>
      <description>&lt;P&gt;Whenever a file is created or modified, splunk will monitor it immediately.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2018 14:24:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-splunk-file-after-restart/m-p/377238#M5816</guid>
      <dc:creator>sudosplunk</dc:creator>
      <dc:date>2018-07-27T14:24:36Z</dc:date>
    </item>
  </channel>
</rss>

