Getting Data In

How do you show sourcetype of a monitor on a Universal Forwarder 5.0.4 via CLI

myou
Explorer

I set a source override for a monitor in Splunk version 5.0.4
Example: splunk add monitor /var/log/maillog-in -sourcetype postfix_syslog

I would like to be able to see that it was successful via the CLI
'splunk list monitor /var/log/maillog-in' does not provide the details.

0 Karma

myou
Explorer

There does not appear to be a way to do this via cli yet. However the information can be shown via a REST point.

https://localhost:8089/services/admin/inputstatus/TailingProcessor:FileStatus

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...