Getting Data In

monitor .bash_history and list monitor

jariw
Path Finder

Hi,

we have got a inputs.conf with :

[monitor:///home/.../.bash_history]
disabled = 0
crcSalt = <SOURCE>
whitelist = \.bash_history$

Just to monitor the .bash_history file.  But when i look at "./splunk list monitor"  it list every file in the /home/... folders.  Besides that.. the splunkd process just uses much cpu. (no wonder with so many files in the "list monitor" i think).

Why is the splunkd on the universal forwarder monitoring every file in the /home/... folders while all he has to do is check .bash_history? What am i doing wrong with this input?

 

thanks in advance

Jari

p.s. Splunk version 8.1.3

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...