Getting Data In

How to continuously monitor a file from a shared folder or path?

Shan
Builder

Hai All,

Please help me out to understand. how to continuously monitor a file from a shared folder or path?

Thanks in advance..

adonio
Ultra Champion

in inputs.conf, add [monitor:///full/path/to/file]
you can also use wildcards to constantly monitor many files:
[monitor:///full/path/to/*.log]
here all the files that ends with .log
read all documentation here:
http://docs.splunk.com/Documentation/Splunk/7.1.2/Data/Monitorfilesanddirectorieswithinputs.conf

hope it hepls

0 Karma

renjith_nair
Legend

Its same as splunk file monitors if you are including the absolute path
Ref : https://docs.splunk.com/Documentation/Splunk/7.1.2/Data/Monitorfilesanddirectorieswithinputs.conf
Are you facing any issues?

---
What goes around comes around. If it helps, hit it with Karma 🙂

Shan
Builder

@renjith.nair

I haven't tried it yet.. Just wanna get some idea about how to do it . So i posted a question.

0 Karma

renjith_nair
Legend

Suggest you to try that first and let the community know if you have any issues.

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

Shan
Builder

@renjith.nair,

No issues.. I'm about to try that one. :-)..

Thanks

0 Karma

ssadanala1
Contributor

Per documentation

[monitor://]
* This directs a file monitor input to watch all files in .
* can be an entire directory or a single file.
* You must specify the input type and then the path, so put three slashes in
your path if you are starting at the root on *nix systems (to include the
slash that indicates an absolute path).

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...