Getting Data In

How to monitor two files with different names in the same directory, and index all duplicate events on my receiver?

New Member

I have two different file names in the same directory on a forwarder. The problem is, the data for both files are the same, so how do I allow all the events to be indexed on my receiver side?

0 Karma

SplunkTrust
SplunkTrust

Monitor individual files instead of the whole directory.

---
If this reply helps you, an upvote would be appreciated.
0 Karma

New Member

How do i monitor individual files ? Is there an example ?

0 Karma

Community Manager
Community Manager

Hi @englishjohn

If the answer by @richgalloway solved your issue, please don't forget to resolve the post by clicking "Accept" directly below his answer. If you're still having issues, please comment with more details.

Thanks!

0 Karma

SplunkTrust
SplunkTrust

In your [monitor://] stanza name, put a path to an individual file instead of to a directory. See http://docs.splunk.com/Documentation/Splunk/6.5.0/Admin/Inputsconf for more.

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes and swag!