Getting Data In

active-only/eatonlylivefiles in Splunk 4.3

matthewpowell
Engager

The "active-only" feature doesn't seem to work in Splunk 4.3:

# splunk add monitor /var/log/messages -active-only true
In handler 'monitor': Argument "eatonlylivefiles" is not supported by this handler.

It's still listed as a feature in "splunk help add" and at http://docs.splunk.com/Documentation/Splunk/latest/Data/MonitorfilesanddirectoriesusingtheCLI.

Has the feature been removed (and if so, is there a reason why it's no longer useful)? Or is this a bug?

Tags (3)
1 Solution

hexx
Splunk Employee
Splunk Employee

As you found out, this option has been taken out of the code base as of Splunk 4.3. The references to it in the CLI documentation and help have been left behind by mistake. I've just removed the reference in the CLI documentation and it will be gone from the CLI help in Splunk 4.3.1.

View solution in original post

hexx
Splunk Employee
Splunk Employee

As you found out, this option has been taken out of the code base as of Splunk 4.3. The references to it in the CLI documentation and help have been left behind by mistake. I've just removed the reference in the CLI documentation and it will be gone from the CLI help in Splunk 4.3.1.

hexx
Splunk Employee
Splunk Employee

This feature has been removed as of Splunk 4.1 because its implementation did not yield satisfactory results and seemed redundant with the improved tailing processor that was introduced with that version.

matthewpowell
Engager

Thanks for the answer. Out of curiosity, do you know why it was removed? Were there problems with the feature, or was it just not all that useful in the first place?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...