- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Cannot search for new file- How do I get Splunk to pick up the file so I can view it in the UI?
kielsd1045
New Member
08-08-2022
01:27 AM
I am creating a new file in the /var/log directory but when I sure for events I get zero result. How do I get Splunk to pick up the file so I can view it in the UI?
Labels (6)
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
diogofgm

SplunkTrust
08-08-2022
02:39 AM
You need to check if you have a monitor input configured in the machine where the file is.
In the machine it self you can use tool to find this
/opt/splunk/bin/splunk btool inputs list --debug monitor
------------
Hope I was able to help you. If so, some karma would be appreciated.
Hope I was able to help you. If so, some karma would be appreciated.
