Getting Data In

How to continuously monitor a file from a shared folder or path?

Shan
Builder

Hai All,

Please help me out to understand. how to continuously monitor a file from a shared folder or path?

Thanks in advance..

adonio
Ultra Champion

in inputs.conf, add [monitor:///full/path/to/file]
you can also use wildcards to constantly monitor many files:
[monitor:///full/path/to/*.log]
here all the files that ends with .log
read all documentation here:
http://docs.splunk.com/Documentation/Splunk/7.1.2/Data/Monitorfilesanddirectorieswithinputs.conf

hope it hepls

0 Karma

renjith_nair
SplunkTrust
SplunkTrust

Its same as splunk file monitors if you are including the absolute path
Ref : https://docs.splunk.com/Documentation/Splunk/7.1.2/Data/Monitorfilesanddirectorieswithinputs.conf
Are you facing any issues?

Happy Splunking!

Shan
Builder

@renjith.nair

I haven't tried it yet.. Just wanna get some idea about how to do it . So i posted a question.

0 Karma

renjith_nair
SplunkTrust
SplunkTrust

Suggest you to try that first and let the community know if you have any issues.

Happy Splunking!
0 Karma

Shan
Builder

@renjith.nair,

No issues.. I'm about to try that one. :-)..

Thanks

0 Karma

ssadanala1
Contributor

Per documentation

[monitor://]
* This directs a file monitor input to watch all files in .
* can be an entire directory or a single file.
* You must specify the input type and then the path, so put three slashes in
your path if you are starting at the root on *nix systems (to include the
slash that indicates an absolute path).

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...