Getting Data In

For inputs.conf, can the time_before_close setting be used with [batch]?

actionabledata
Path Finder

Follow on question to https://community.splunk.com/t5/Getting-Data-In/Can-batch-read-a-partial-file-such-that-the-of-event...

[Q] For inputs.conf, can the time_before_close setting be used with [batch]?

The inputs.conf file specifically indicates which [monitor] settings are compatible with [batch] and this setting is not included.

https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf

From inputs.conf

 The following settings work identically as for [monitor::] stanzas,
 documented above
host_regex = <regular expression>
host_segment = <integer>
crcSalt = <string>
recursive = <boolean>
whitelist = <regular expression>
blacklist = <regular expression>
initCrcLength = <integer>

 

 

Labels (1)
0 Karma

splunkyj
Path Finder

This is no longer the case. See https://docs.splunk.com/Documentation/Splunk/latest/admin/Inputsconf

# The following settings work identically as for [monitor::] stanzas,
# documented previously
host_regex = <regular expression>
host_segment = <integer>
crcSalt = <string>
recursive = <boolean>
whitelist = <regular expression>
blacklist = <regular expression>
initCrcLength = <integer>
time_before_close = <integer>
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...