<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can I monitor a filepath effectively? in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-I-monitor-a-filepath-effectively/m-p/649671#M9702</link>
    <description>&lt;P&gt;I have been attempting to add a file path in data inputs as well as in the inputs.conf file as a "monitor".&amp;nbsp; Each time I implement this Splunk ingestion latency spikes to over 300ms and the service becomes effectively unusable.&lt;/P&gt;
&lt;P&gt;My intention is to monitor file additions, deletions, and modifications within a specific filepath.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jul 2023 16:10:14 GMT</pubDate>
    <dc:creator>kymenope</dc:creator>
    <dc:date>2023-07-10T16:10:14Z</dc:date>
    <item>
      <title>How can I monitor a filepath effectively?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-I-monitor-a-filepath-effectively/m-p/649671#M9702</link>
      <description>&lt;P&gt;I have been attempting to add a file path in data inputs as well as in the inputs.conf file as a "monitor".&amp;nbsp; Each time I implement this Splunk ingestion latency spikes to over 300ms and the service becomes effectively unusable.&lt;/P&gt;
&lt;P&gt;My intention is to monitor file additions, deletions, and modifications within a specific filepath.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 16:10:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-can-I-monitor-a-filepath-effectively/m-p/649671#M9702</guid>
      <dc:creator>kymenope</dc:creator>
      <dc:date>2023-07-10T16:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a filepath effectively</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-I-monitor-a-filepath-effectively/m-p/649689#M9703</link>
      <description>&lt;P&gt;&lt;EM&gt;the ingestion latency of 300 milli seconds&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;you meant to say, the 300 MS is a huge delay? may we know what delay you are expecting? pls let us know more details about the requirements, so that we can understand it and suggest you a solution. thanks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Best Regards,&lt;BR /&gt;Sekar&lt;/P&gt;&lt;P&gt;my youtube channel for Splunk Newbie Learnings&lt;BR /&gt;&lt;A href="https://www.youtube.com/@SiemNewbies101/videos" target="_blank"&gt;https://www.youtube.com/@SiemNewbies101/videos&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 21:45:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-can-I-monitor-a-filepath-effectively/m-p/649689#M9703</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2023-07-07T21:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a filepath effectively</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-I-monitor-a-filepath-effectively/m-p/649690#M9704</link>
      <description>&lt;P&gt;once I enable the data input I am unable to use Splunk whatsoever due to this ingestion latency.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have assigned the inputs a sourcetype but querying for said search type always returns no results.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 21:49:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-can-I-monitor-a-filepath-effectively/m-p/649690#M9704</guid>
      <dc:creator>kymenope</dc:creator>
      <dc:date>2023-07-07T21:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a filepath effectively</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-can-I-monitor-a-filepath-effectively/m-p/649692#M9705</link>
      <description>&lt;P&gt;maybe you should provide us more details pls..&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) the UF ... linux or win..&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) do you have HF or not&lt;/P&gt;&lt;P&gt;3)the indexers... is it basic single indexer or you have clusters&lt;/P&gt;&lt;P&gt;4)did you do any upgrades recently on the indexer(s)?!?!&amp;nbsp;&lt;/P&gt;&lt;P&gt;5) is it regular log file data onboarding or is it scripted input or HEC or something else..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 21:56:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-can-I-monitor-a-filepath-effectively/m-p/649692#M9705</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2023-07-07T21:56:09Z</dc:date>
    </item>
  </channel>
</rss>

