Getting Data In

How to find status of files being monitored?

wdsjon
Engager

Is there a command or somewhere to look regarding the status of file monitoring? I've set up a UF on an rsyslog machine with tons or currently residing text log files in nested directories that I've created a monitoring stanza for in an inputs.conf. Question - Is there a way from the universal forwarder to see the status of the files it's reading? I've been able to get sort of an idea with lsof , but some of the files are 50GB+. Thanks!

1 Solution

jnussbaum_splun
Splunk Employee
Splunk Employee
$SPLUNK_HOME/bin/splunk _internal call /services/admin/inputstatus/TailingProcessor:FileStatus

should get you done.

View solution in original post

jnussbaum_splun
Splunk Employee
Splunk Employee
$SPLUNK_HOME/bin/splunk _internal call /services/admin/inputstatus/TailingProcessor:FileStatus

should get you done.

robertlynch2020
Influencer

Sorry i am gettign this when i do that

 

bash$ splunk _internal call /services/admin/inputstatus/TailingProcessor:FileStatus
QUERYING: 'https://127.0.0.1:9089/services/admin/inputstatus/TailingProcessor:FileStatus'
This command [GET /services/admin/inputstatus/TailingProcessor:FileStatus] needs splunkd to be up, and splunkd is down.
dell425srv autoengine /dell425srv3/apps/AMBER_FWD/splunkforwarder_AMBER_PSC47_SEC1/splunkforwarder/bin/
bash$

0 Karma

martin_mueller
SplunkTrust
SplunkTrust
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...