All Apps and Add-ons

What is the use of batch and move_policy = sinkhole?

VijaySrrie
Builder

Hi All,

What is the use of 

move_policy = sinkhole

and on which scenario we will use batch (Batch will index the file and delete but in which application or server this should be used?) 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The move_policy setting is required with a batch input as a way of making sure the admin understands what he or she is doing.  A batch input might be used to index a file that will not be updated.

---
If this reply helps you, Karma would be appreciated.
0 Karma

VijaySrrie
Builder

what happens when move_policy setting is not given in the batch config?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I believe the batch input will be ignored if move_policy is missing.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2023 Splunk Career Impact Report

We’ve been shouting it from the rooftops! The findings from the 2023 Splunk Career Impact Report showing that ...

Splunk Lantern | Getting Started with Edge Processor, Machine Learning Toolkit ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...