Monitoring Splunk

Cannot search for new file- How do I get Splunk to pick up the file so I can view it in the UI?

kielsd1045
New Member

I am creating a new file in the /var/log directory but when I sure for events I get zero result. How do I get Splunk to pick up the file so I can view it in the UI?

0 Karma

diogofgm
SplunkTrust
SplunkTrust

You need to check if you have a monitor input configured in the machine where the file is.

In the machine it self you can use tool to find this

/opt/splunk/bin/splunk btool inputs list --debug monitor
------------
Hope I was able to help you. If so, some karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...