Getting Data In

How do I monitor files in a folder as well as the files in all subfolders?

andyk
Path Finder

Hi,

I want to monitor the files in E:\data\pnlog as well as all the files in the subfolders. Is there any way to simplify this or a way to get this done in one stanza?

[monitor://E:\Data\pnlog\...\*]
whitelist = \.log$
disabled = false
followTail = 0
_TCP_ROUTING = pnlogGroup

[monitor://E:\Data\pnlog\*]
whitelist = \.log$
disabled = false
followTail = 0
_TCP_ROUTING = pnlogGroup

// Andreas

1 Solution

ziegfried
Influencer

If you define a monitor on a folder, it is recursive by default. So if you specify

[monitor://E:\Data\pnlog]
whitelist = \.log$
disabled = false
followTail = 0
_TCP_ROUTING = pnlogGroup

It will montor all files recursivly that match the whitelist expression.

View solution in original post

ziegfried
Influencer

If you define a monitor on a folder, it is recursive by default. So if you specify

[monitor://E:\Data\pnlog]
whitelist = \.log$
disabled = false
followTail = 0
_TCP_ROUTING = pnlogGroup

It will montor all files recursivly that match the whitelist expression.

ziegfried
Influencer

Yes. Quote "If the specified directory contains subdirectories, Splunk recursively examines them for new files." in http://www.splunk.com/base/Documentation/latest/Admin/Monitorfilesanddirectories

0 Karma

andyk
Path Finder

Thank you! Is this to be found in the documentation?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...