Getting Data In

Where is the default value of time_before_close property defined in splunk?

iparitosh
Path Finder

I could not find this property under $SPLUNK_HOME$/system/default/inputs.conf

time_before_close =
* The amount of time, in seconds, that the file monitor must wait for
modifications before closing a file after reaching an End-of-File
(EOF) marker.
* Tells the input not to close files that have been updated in the
past 'time_before_close' seconds.
* Default: 3.

0 Karma
1 Solution

DavidHourani
Super Champion

Hi @iparitosh,

The default value is defined in the documentation here as 3 seconds :
https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf

I ran a search on all .conf files and it's not defined there as well. It should be hard coded somewhere in the core configuration as this parameter is a core functionality for the monitoring stanza in inputs.conf.

Cheers,
David

View solution in original post

DavidHourani
Super Champion

Hi @iparitosh,

The default value is defined in the documentation here as 3 seconds :
https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf

I ran a search on all .conf files and it's not defined there as well. It should be hard coded somewhere in the core configuration as this parameter is a core functionality for the monitoring stanza in inputs.conf.

Cheers,
David

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...