Getting Data In

For inputs.conf, can the time_before_close setting be used with [batch]?

actionabledata
Path Finder

Follow on question to https://community.splunk.com/t5/Getting-Data-In/Can-batch-read-a-partial-file-such-that-the-of-event...

[Q] For inputs.conf, can the time_before_close setting be used with [batch]?

The inputs.conf file specifically indicates which [monitor] settings are compatible with [batch] and this setting is not included.

https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf

From inputs.conf

 The following settings work identically as for [monitor::] stanzas,
 documented above
host_regex = <regular expression>
host_segment = <integer>
crcSalt = <string>
recursive = <boolean>
whitelist = <regular expression>
blacklist = <regular expression>
initCrcLength = <integer>

 

 

Labels (1)
0 Karma

splunkyj
Path Finder

This is no longer the case. See https://docs.splunk.com/Documentation/Splunk/latest/admin/Inputsconf

# The following settings work identically as for [monitor::] stanzas,
# documented previously
host_regex = <regular expression>
host_segment = <integer>
crcSalt = <string>
recursive = <boolean>
whitelist = <regular expression>
blacklist = <regular expression>
initCrcLength = <integer>
time_before_close = <integer>
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...