Monitoring Splunk

How can I monitor a filepath effectively?

kymenope
Explorer

I have been attempting to add a file path in data inputs as well as in the inputs.conf file as a "monitor".  Each time I implement this Splunk ingestion latency spikes to over 300ms and the service becomes effectively unusable.

My intention is to monitor file additions, deletions, and modifications within a specific filepath.

 

Any ideas?

Labels (1)
0 Karma

kymenope
Explorer

once I enable the data input I am unable to use Splunk whatsoever due to this ingestion latency. 

I have assigned the inputs a sourcetype but querying for said search type always returns no results.

0 Karma

inventsekar
SplunkTrust
SplunkTrust

maybe you should provide us more details pls.. 

1) the UF ... linux or win.. 

2) do you have HF or not

3)the indexers... is it basic single indexer or you have clusters

4)did you do any upgrades recently on the indexer(s)?!?! 

5) is it regular log file data onboarding or is it scripted input or HEC or something else.. 

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

inventsekar
SplunkTrust
SplunkTrust

the ingestion latency of 300 milli seconds

you meant to say, the 300 MS is a huge delay? may we know what delay you are expecting? pls let us know more details about the requirements, so that we can understand it and suggest you a solution. thanks. 


Best Regards,
Sekar

my youtube channel for Splunk Newbie Learnings
https://www.youtube.com/@SiemNewbies101/videos

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...

Index This | How many sevens are there between 1 and 100?

August 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...