Getting Data In

Directory monitoring

DonDandrea
Path Finder

Is it possible to monitor a directory with Splunk? When I say monitor a directory I am not interested in the contents of the files in the directory. I am an interested in logging the filenames and timestamps of the files in the directory.

Tags (2)
0 Karma

lguinn2
Legend

Yes, the feature is called "fschange monitor" and you use it like this in inputs.conf

[fschange:<path>]

However, the feature is deprecated (although it hasn't been removed yet), so you might want to look at this
fschange deprecated, what are the options

Also, Splunk cannot do fschange and a regular monitor over the same files/directories.

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk &#43; Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...