Getting Data In

Are there adverse affects to having monitors for files that do not exist?

brent_weaver
Builder

I have two platforms to monitor. I want to create one application that I can apply to all hosts that come on board. I know that Spunk will not scream anymore with 6.2.x, but are there adverse affects? Will it create errors in the Spunk log files?

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You won't see any errors, not finding a file is expected behaviour. You also won't see any performance issues if you keep the number of monitors reasonable. You might see unexpected indexing if one platform one day happens to create a file in a path that exists in the other platform.

For clarity, maintenance, extendability, fewer cross-platform dependencies, etc. I'd advise to create two tailored apps nonetheless.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...