Getting Data In

Can I monitor a file with extension .splunk?

btawiah
Explorer

Trying to monitor a file that ends with .splunk but for some reason splunk will not index it. Only when I change the extension to .txt, it ingests. Any reasons why this is happening?

Thanks

0 Karma
1 Solution

cvssravan
Path Finder

@btawiah
This is the reason:

Files with a .splunk filename extension are also not monitored, because files with that extension contain Splunk metadata. If you need to index files with a .splunk extension, use the add oneshot CLI command.

You can read more here:
https://docs.splunk.com/Documentation/Splunk/7.2.4/Data/Monitorfilesanddirectories

View solution in original post

cvssravan
Path Finder

@btawiah
This is the reason:

Files with a .splunk filename extension are also not monitored, because files with that extension contain Splunk metadata. If you need to index files with a .splunk extension, use the add oneshot CLI command.

You can read more here:
https://docs.splunk.com/Documentation/Splunk/7.2.4/Data/Monitorfilesanddirectories

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Using the Splunk Threat Research Team’s Latest Security Content

REGISTER HERE Tech Talk | Security Edition Did you know the Splunk Threat Research Team regularly releases ...

SplunkTrust | 2024 SplunkTrust Application Period is Open!

It's that time again, folks! That's right, the application/nomination period for the 2024 SplunkTrust is ...