Getting Data In

Index just filenames in a directory

cejohnson
Explorer

Is it possible to just index a directory of filenames? I have a directory containing gobs of logfiles. I really don't need the data from them, but the filenames contain enough info that I could do some easy counts and stats using splunk.

Tags (1)
0 Karma

lrhazi
Path Finder

Your data source could be a script that runs /bin/ls /path/to/your/dir

0 Karma

cejohnson
Explorer

I'm not sure that would work for me. One of the things I'd like to do is continually monitor the directory and display the counts of some of the different file types that show up in there, updating the dashboard every X number of minutes. I'm able to determine the different file types based on the naming convention.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...