Hello Splunk Experts,
I have a folder that i need to monitored entirely:
the folder contains a list that is represented by the following:
namefile1_yyyymmdd.csv
namefile2_yyyymmdd.csv
namefile3_yyyymmdd.csv
each day this folder will contains CSV's from yesterday,
How splunk could monitor automatically such folder?
Thanks,
vi inputs.conf
[monitor:///home/splunk/devicescollect/AgentsReads]
disabled = false
followTail = 0
host = dcpcontroller.wavemark.net
sourcetype = AgentsReads
crcSalt=
The above line will tell splunk to monitor the entire directory , there are mainly 3 directories created ( folders)
-AgentsReads
-DevicesReads
-DevicesInfo
I need from splunk to monitor only files of yesterday in that folder to reduce CPU consumption. I found that i can use ignoreOlderThan =
With an ordinary [monitor:///path/to/files]
. Splunk will read all the files in the directory by default.
Not sure I understand the problem - what's stopping you from simply monitoring the directory?