Assuming your Splunk server is running on your local computer, all you need is an inputs.conf entry like this:
[monitor:///path/to/your/folder]
index = your_index
sourcetype = your_sourcetype
Splunk will then constantly index new lines added to files in that folder.
Yes, edit $SPLUNK_HOME/etc/system/local/inputs.conf
and add it like this:
[monitor://C:\users\*\desktop\splunkme\*]
index=main
sourcetype=constant_deskctop_sync
Got it to work.. Thanks
Where will I be doing this?
On your desktop server after you install Splunk there (which I thought you had already done).
Assuming your Splunk server is running on your local computer, all you need is an inputs.conf entry like this:
[monitor:///path/to/your/folder]
index = your_index
sourcetype = your_sourcetype
Splunk will then constantly index new lines added to files in that folder.
This has an explanation of common keys used: http://docs.splunk.com/Documentation/Splunk/6.2.3/Data/Editinputs.conf
I got it to work! Thanks
I found the inputs.config file... Right now all I have is the host = xxxxxxxxxxxxxxxxxx
And then I added your lines...
[monitor:\C:\Users......]
index=??
sourcetype=???
My sourcetype changes and what is index?
Where will I be doing this?
If you are new to the configuration file system, definitely read the documentation topics starting with About configuration files in the Admin Manual. You need to understand the directory structure and precedence.
If Im doing it with Splunk web using localhost where would I find the config files?
If you're on Windows, typically C:\Program Files\Splunk\etc
.