Getting Data In

Can you track the size of a log file?

flyers777
Explorer

I've been browsing around and was wondering is there a way to track a specific log file size (source)? The main reason I want to have an alert that if that files gets too big to have Splunk kick of a script to archive it. I really haven't been able to find a way to do this and was just wondering if anyone else has ran into this issue? Thanks everyone for your help.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @flyers777,
you could run a script that extract the size of files using a simple dir command (in Windows) or an ls -la command (in Linux) sending the output to Splunk, then you can run a search that compares values alerting it it reach a threeshold.

You can find infos at https://docs.splunk.com/Documentation/Splunk/8.0.1/AdvancedDev/ScriptSetup but in few words:

  • you have to create a script in $SPLUNK_HOME/etc/apps/your_app/bin e.g. called ls.sh (in Linux),
  • give to the script the correct execution rights,
  • create a stanza in inputs.conf to schedule script.

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...