Getting Data In

active-only/eatonlylivefiles in Splunk 4.3

matthewpowell
Engager

The "active-only" feature doesn't seem to work in Splunk 4.3:

# splunk add monitor /var/log/messages -active-only true
In handler 'monitor': Argument "eatonlylivefiles" is not supported by this handler.

It's still listed as a feature in "splunk help add" and at http://docs.splunk.com/Documentation/Splunk/latest/Data/MonitorfilesanddirectoriesusingtheCLI.

Has the feature been removed (and if so, is there a reason why it's no longer useful)? Or is this a bug?

Tags (3)
1 Solution

hexx
Splunk Employee
Splunk Employee

As you found out, this option has been taken out of the code base as of Splunk 4.3. The references to it in the CLI documentation and help have been left behind by mistake. I've just removed the reference in the CLI documentation and it will be gone from the CLI help in Splunk 4.3.1.

View solution in original post

hexx
Splunk Employee
Splunk Employee

As you found out, this option has been taken out of the code base as of Splunk 4.3. The references to it in the CLI documentation and help have been left behind by mistake. I've just removed the reference in the CLI documentation and it will be gone from the CLI help in Splunk 4.3.1.

hexx
Splunk Employee
Splunk Employee

This feature has been removed as of Splunk 4.1 because its implementation did not yield satisfactory results and seemed redundant with the improved tailing processor that was introduced with that version.

matthewpowell
Engager

Thanks for the answer. Out of curiosity, do you know why it was removed? Were there problems with the feature, or was it just not all that useful in the first place?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...