<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blacklist files greater than a certain size from inputs.conf in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Blacklist-files-greater-than-a-certain-size-from-inputs-conf/m-p/408639#M117975</link>
    <description>&lt;P&gt;Hi HiroshiSatoh,&lt;/P&gt;

&lt;P&gt;Reading the inputs.conf documentation it seems the "fschange" is deprecated since version 5.0&lt;BR /&gt;
I will probably go with a UNIX script that works in that way:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Find all the files in folder A that:&lt;BR /&gt;
are not older than 1 day&lt;BR /&gt;
are closed&lt;BR /&gt;
have a size lower than 10MB&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;based on the files found at point 1, generate symbolic links in folder B&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Monitor with Splunk the symbolic links in folder B&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Cancel symbolic links older than 2 days&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Best Regards,&lt;BR /&gt;
Edoardo&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jun 2018 12:25:57 GMT</pubDate>
    <dc:creator>edoardo_vicendo</dc:creator>
    <dc:date>2018-06-26T12:25:57Z</dc:date>
    <item>
      <title>Blacklist files greater than a certain size from inputs.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Blacklist-files-greater-than-a-certain-size-from-inputs-conf/m-p/408634#M117970</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I have to monitor a folder where there are very huge files with file name automatically generated.&lt;BR /&gt;
Is there some way (instead of write a custom UNIX script that moves only small files to another folder that will be then monitored by the forwarder) to blacklist files that have a size greater than (suppose) 10 MB?&lt;/P&gt;

&lt;P&gt;Any other suggestion with Splunk stanza attributes is appreciated.&lt;/P&gt;

&lt;P&gt;Thanks a lot,&lt;BR /&gt;
Edoardo&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 14:43:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Blacklist-files-greater-than-a-certain-size-from-inputs-conf/m-p/408634#M117970</guid>
      <dc:creator>edoardo_vicendo</dc:creator>
      <dc:date>2018-06-25T14:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklist files greater than a certain size from inputs.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Blacklist-files-greater-than-a-certain-size-from-inputs-conf/m-p/408635#M117971</link>
      <description>&lt;P&gt;hello there,&lt;BR /&gt;
if the files have some naming convention you can follow, you can apply rules based on their name.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 23:44:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Blacklist-files-greater-than-a-certain-size-from-inputs-conf/m-p/408635#M117971</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2018-06-25T23:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklist files greater than a certain size from inputs.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Blacklist-files-greater-than-a-certain-size-from-inputs-conf/m-p/408636#M117972</link>
      <description>&lt;P&gt;It can not be executed because there is no size limit parameter in "monitor".&lt;BR /&gt;
If it is "fschange", it may be restricted by "endEventMaxSize". However, it captures the entire file, not differential import.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 01:10:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Blacklist-files-greater-than-a-certain-size-from-inputs-conf/m-p/408636#M117972</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2018-06-26T01:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklist files greater than a certain size from inputs.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Blacklist-files-greater-than-a-certain-size-from-inputs-conf/m-p/408637#M117973</link>
      <description>&lt;P&gt;Hi Adonio,&lt;/P&gt;

&lt;P&gt;Unfortunately there is no logic in the file name.&lt;/P&gt;

&lt;P&gt;Thanks a lot,&lt;BR /&gt;
Edoardo&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 11:57:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Blacklist-files-greater-than-a-certain-size-from-inputs-conf/m-p/408637#M117973</guid>
      <dc:creator>edoardo_vicendo</dc:creator>
      <dc:date>2018-06-26T11:57:14Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklist files greater than a certain size from inputs.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Blacklist-files-greater-than-a-certain-size-from-inputs-conf/m-p/408638#M117974</link>
      <description>&lt;P&gt;@HiroshiSatoh has the right answer imho&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 12:16:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Blacklist-files-greater-than-a-certain-size-from-inputs-conf/m-p/408638#M117974</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2018-06-26T12:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklist files greater than a certain size from inputs.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Blacklist-files-greater-than-a-certain-size-from-inputs-conf/m-p/408639#M117975</link>
      <description>&lt;P&gt;Hi HiroshiSatoh,&lt;/P&gt;

&lt;P&gt;Reading the inputs.conf documentation it seems the "fschange" is deprecated since version 5.0&lt;BR /&gt;
I will probably go with a UNIX script that works in that way:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Find all the files in folder A that:&lt;BR /&gt;
are not older than 1 day&lt;BR /&gt;
are closed&lt;BR /&gt;
have a size lower than 10MB&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;based on the files found at point 1, generate symbolic links in folder B&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Monitor with Splunk the symbolic links in folder B&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Cancel symbolic links older than 2 days&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Best Regards,&lt;BR /&gt;
Edoardo&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 12:25:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Blacklist-files-greater-than-a-certain-size-from-inputs-conf/m-p/408639#M117975</guid>
      <dc:creator>edoardo_vicendo</dc:creator>
      <dc:date>2018-06-26T12:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklist files greater than a certain size from inputs.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Blacklist-files-greater-than-a-certain-size-from-inputs-conf/m-p/408640#M117976</link>
      <description>&lt;P&gt;fschange has not been deleted yet. It is convenient so I am using it now.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 12:46:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Blacklist-files-greater-than-a-certain-size-from-inputs-conf/m-p/408640#M117976</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2018-06-26T12:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklist files greater than a certain size from inputs.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Blacklist-files-greater-than-a-certain-size-from-inputs-conf/m-p/408641#M117977</link>
      <description>&lt;P&gt;i recommend not to use symbolic link, splunk is not always good in understanding it with the monitor stanza&lt;BR /&gt;
better find files matching criteria - &amp;gt; copy to a new directory -&amp;gt; monitor that directory&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 13:44:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Blacklist-files-greater-than-a-certain-size-from-inputs-conf/m-p/408641#M117977</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2018-06-26T13:44:29Z</dc:date>
    </item>
    <item>
      <title>Re: Blacklist files greater than a certain size from inputs.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Blacklist-files-greater-than-a-certain-size-from-inputs-conf/m-p/408642#M117978</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;At the end I went with a UNIX script that works in that way:&lt;/P&gt;

&lt;P&gt;Find all the files in folder A that:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;are not older than 5 minutes (see find with -mtime) &lt;/LI&gt;
&lt;LI&gt;are closed&lt;/LI&gt;
&lt;LI&gt;have a size lower than 16KB (that in my case means around 400 lines)&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Those files will be then copied in the folder moniterd in batch mode by the forwarder.&lt;BR /&gt;
For the files greater than 16KB I have done a head -200 and tail -200 and copied as well with the same original file name in the folder moniterd in batch mode by the forwarder.&lt;/P&gt;

&lt;P&gt;Thanks to all for your suggestions!&lt;/P&gt;

&lt;P&gt;Best Regards,&lt;BR /&gt;
Edoardo&lt;/P&gt;</description>
      <pubDate>Mon, 05 Nov 2018 17:24:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Blacklist-files-greater-than-a-certain-size-from-inputs-conf/m-p/408642#M117978</guid>
      <dc:creator>edoardo_vicendo</dc:creator>
      <dc:date>2018-11-05T17:24:24Z</dc:date>
    </item>
  </channel>
</rss>

