Getting Data In

Move indexed file!

erick_costa
Path Finder

How to do to move files indexed by splunk?

[monitor:///var/log/teste/teste.log]

Tags (3)
0 Karma

erick_costa
Path Finder

I want to move to another folder!

eg. \backup\logs\

0 Karma

Lucas_K
Motivator

I assume your talking about the source log files?

It all depends on what you are trying to do and how your logs are generated.
Are they rolling, appended to or created freshly each time? That would determine what sort of input you should be using.

As you are using a monitor statement there are no parameters to do anything with the file once it has been read, it just monitors (ie. reads) the file for new events. It is a non-destructive process.

If your looking to delete the file once it is read they you need to look at using a different type of input stanza that has a move_policy option such as batch ( http://docs.splunk.com/Documentation/Splunk/6.0.1/admin/inputsconf ).

move_policy = sinkhole
  • IMPORTANT: This attribute/value pair is required. You must include "move_policy = sinkhole" when defining batch inputs.
  • This loads the file destructively.
  • Do not use the batch input type for files you do not want to consume destructively.
  • As long as this is set, Splunk won't keep track of indexed files. Without the "move_policy = sinkhole" setting, it won't load the files destructively and will keep a track of them.

Normally you would use that for uniquely logs that are placed into your filesystem by another process ie. ftp-ed in etc etc.

erick_costa
Path Finder

I want to move to another folder!

eg. \backup\logs\

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...