<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TailingProcessor File Status without port 8089? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/TailingProcessor-File-Status-without-port-8089/m-p/109566#M183526</link>
    <description>&lt;P&gt;You can call the endpoint directly from the CLI:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;./splunk _internal call /services/admin/inputstatus/TailingProcessor:FileStatus
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 27 Mar 2014 16:36:08 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2014-03-27T16:36:08Z</dc:date>
    <item>
      <title>TailingProcessor File Status without port 8089?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/TailingProcessor-File-Status-without-port-8089/m-p/109564#M183524</link>
      <description>&lt;P&gt;We would like to have forwarders run as root in order to overcome file permissions. However, we also will be security hardening it as much as possible. One of these measures is to stop port 8089 on the forwarder. I assume this will not give us the ability to read the REST endpoint &lt;A href="https://hostname:8089/services/admin/inputstatus/TailingProcessor%3AFileStatus"&gt;https://hostname:8089/services/admin/inputstatus/TailingProcessor%3AFileStatus&lt;/A&gt;. Are there any other ways to gather this data without the REST endpoint being available?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2014 14:16:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/TailingProcessor-File-Status-without-port-8089/m-p/109564#M183524</guid>
      <dc:creator>vcarbona</dc:creator>
      <dc:date>2014-03-27T14:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: TailingProcessor File Status without port 8089?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/TailingProcessor-File-Status-without-port-8089/m-p/109565#M183525</link>
      <description>&lt;P&gt;How about using search?&lt;BR /&gt;
index=_internal component=TailingProcessor&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2014 16:21:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/TailingProcessor-File-Status-without-port-8089/m-p/109565#M183525</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-03-27T16:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: TailingProcessor File Status without port 8089?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/TailingProcessor-File-Status-without-port-8089/m-p/109566#M183526</link>
      <description>&lt;P&gt;You can call the endpoint directly from the CLI:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;./splunk _internal call /services/admin/inputstatus/TailingProcessor:FileStatus
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 27 Mar 2014 16:36:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/TailingProcessor-File-Status-without-port-8089/m-p/109566#M183526</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-03-27T16:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: TailingProcessor File Status without port 8089?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/TailingProcessor-File-Status-without-port-8089/m-p/109567#M183527</link>
      <description>&lt;P&gt;That would have been cool, but I get this:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;ps -ef|grep splunk&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;splunk     5604     1 53 11:39 ?        00:00:13 splunkd -p 8089 restart&lt;BR /&gt;
splunk     5605  5604  0 11:39 ?        00:00:00 [splunkd pid=5604] splunkd -p 8089 restart [process-runner]&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;./splunk _internal call /services/admin/inputstatus/TailingProcessor:FileStatus&lt;BR /&gt;
QUERYING: '&lt;A href="https://127.0.0.1:8089/services/admin/inputstatus/TailingProcessor:FileStatus"&gt;https://127.0.0.1:8089/services/admin/inputstatus/TailingProcessor:FileStatus&lt;/A&gt;'&lt;BR /&gt;
This command [GET /services/admin/inputstatus/TailingProcessor:FileStatus] needs splunkd to be up, and splunkd is down.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Thu, 27 Mar 2014 16:43:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/TailingProcessor-File-Status-without-port-8089/m-p/109567#M183527</guid>
      <dc:creator>vcarbona</dc:creator>
      <dc:date>2014-03-27T16:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: TailingProcessor File Status without port 8089?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/TailingProcessor-File-Status-without-port-8089/m-p/109568#M183528</link>
      <description>&lt;P&gt;So you've made port 8089 unavailable even from localhost? Then it might indeed be tough to call the REST API.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2014 17:19:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/TailingProcessor-File-Status-without-port-8089/m-p/109568#M183528</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-03-27T17:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: TailingProcessor File Status without port 8089?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/TailingProcessor-File-Status-without-port-8089/m-p/109569#M183529</link>
      <description>&lt;P&gt;Thanks! This actually helped us to identify some problem areas. But it appears conditions like "ignored file (crc conflict, needs crcSalt)" or "File did not match whitelist ..." do not show up.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2014 18:45:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/TailingProcessor-File-Status-without-port-8089/m-p/109569#M183529</guid>
      <dc:creator>vcarbona</dc:creator>
      <dc:date>2014-03-27T18:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: TailingProcessor File Status without port 8089?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/TailingProcessor-File-Status-without-port-8089/m-p/109570#M183530</link>
      <description>&lt;P&gt;I noticed the btprobe command shows some interesting data about the file status. It appears it is able to retrieve the modtime and seek pointer. Is it correct to assume that sptr (or seek pointer) is where the forwarder left off reading the file?&lt;/P&gt;

&lt;P&gt;splunk cmd btprobe -d /opt/splunkforwarder/var/lib/splunk/fishbucket/splunk_private_db --file /var/log/messages&lt;/P&gt;

&lt;P&gt;Using logging configuration at /opt/splunkforwarder/6.0.3-204106/etc/log-cmdline.cfg.&lt;BR /&gt;
key=0xf4e82f9f021c429d scrc=0xc6e25d94afc02135 sptr=871 fcrc=0x452905a167cf4509 flen=0 mdtm=1404740503 wrtm=1404740504&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:00:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/TailingProcessor-File-Status-without-port-8089/m-p/109570#M183530</guid>
      <dc:creator>vcarbona</dc:creator>
      <dc:date>2020-09-28T17:00:28Z</dc:date>
    </item>
    <item>
      <title>Re: TailingProcessor File Status without port 8089?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/TailingProcessor-File-Status-without-port-8089/m-p/109571#M183531</link>
      <description>&lt;P&gt;Actually "ignored file (crc conflict, needs crcSalt)" does appear, it just has a different error. I run it as "index=_internal component=TailingProcessor ERROR salt". It shows up as an ERROR alert level. The "File did not match whitelist ..." appears when I set TailingProcessor to DEBUG level.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jul 2014 17:50:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/TailingProcessor-File-Status-without-port-8089/m-p/109571#M183531</guid>
      <dc:creator>vcarbona</dc:creator>
      <dc:date>2014-07-08T17:50:46Z</dc:date>
    </item>
  </channel>
</rss>

