Getting Data In

Recursively monitor files in current directory and subdirectories upto a specified maxDepth

tusharsaran1
Path Finder

Is it possible to recursively monitor the files in a directory tree but only till a specified maxDepth?
Example: I have a stanza in inputs.conf which says [monitor://A/B/]
I want to monitor directories /A/B/C, /A/B/D
I don't want to monitor directories /A/B/C/X or /A/B/D/Y

Basically, anything which is deeper than 2 levels inside /A/B should not be monitored. Is it possible to implement this?

0 Karma

DalJeanis
Legend

Lots of ways. You don't need recursion for this, just wildcarding to the desired depth.

Alternately, you could also just blacklist anything beyond the requested depth, if that is easier to specify.

I don't play with those much, but that might look something like this...

 [monitor://A/B/]
 blacklist: //A/B/*/.../* 
0 Karma

ddrillic
Ultra Champion

Maybe be explicit about what you want to monitor and set recursive = false....

I just don't see a depth parameter in Edit inputs.conf

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...