Getting Data In

How to monitor Directory in splunk

Thenmozhi
New Member

Hi,

We are trying to monitor directory using splunk.Using Files & Directory data inputs,we are unable to monitor directory.We have only file browser and when we try to click a directory SELCECT option is disabled and only if we click on files SELECT option is getting enabled.Do we have to make any configuration changes to enable directory monitoring???.

Regards,
Thenmozhi

Tags (2)
0 Karma

okrabbe_splunk
Splunk Employee
Splunk Employee

I suspect you are trying to preview the data. Preview only works with one file.

When you want to monitor a whole directory skip the preview:
A File or Directory -> Consume any file on the server -> Skip preview

Then select the radio button - "Continuously index data from a file or directory this Splunk instance can access" and enter the path in the input box.

0 Karma
Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Enhance Security Operations with Automated Threat Analysis in the Splunk EcosystemAre you leveraging ...

Splunk Developers: Go Beyond the Dashboard with These .Conf25 Sessions

  Whether you’re building custom apps, diving into SPL2, or integrating AI and machine learning into your ...

Index This | How do you write 23 only using the number 2?

July 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...