Getting Data In

How to stop monitoring a particular log file name in Splunk?

gunturu_nagasri
Explorer

Log path being monitored /tmp/*.log

I have numerous files under the log path that are being monitored. How I can stop monitoring only a particular log file e.g. : abc.log, from the path /tmp?

0 Karma

sanjeev543
Communicator

You can try this way

[monitor:///tmp/*.log]
blacklist = abc.log

sundareshr
Legend
0 Karma
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...