Getting Data In

Is there some way to see the current tailing status?

the_wolverine
Champion

Is there a splunk command or REST endpoint to see the tailing status of monitored files?

Tags (3)
1 Solution

the_wolverine
Champion

Try hitting this url:

https://yoursplunkhost:8089/services/admin/inputstatus/TailingProcessor%3AFileStatus
  • replace yoursplunkhost with your splunk server name
  • replace 8089 with your configured mgmt port number.

This only works if you changed the admin password on the Splunk instance/universal forwarder.

Otherwise you can run this command on the host:

./splunk _internal call /services/admin/inputstatus/TailingProcessor:FileStatus

View solution in original post

the_wolverine
Champion

Try hitting this url:

https://yoursplunkhost:8089/services/admin/inputstatus/TailingProcessor%3AFileStatus
  • replace yoursplunkhost with your splunk server name
  • replace 8089 with your configured mgmt port number.

This only works if you changed the admin password on the Splunk instance/universal forwarder.

Otherwise you can run this command on the host:

./splunk _internal call /services/admin/inputstatus/TailingProcessor:FileStatus

jrodman
Splunk Employee
Splunk Employee

This is a great question, if only it had an answer. Oh wait?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...