Monitoring Splunk

Output of 'splunk list monitor'

dwaddle
SplunkTrust
SplunkTrust

Is the output of 'splunk list monitor' clipped at all?

I have a directory with (approx) 50 log files, but the output only shows 30 or so. I know the additional 20 are being indexed, because I have events from them.

Also, does a deleted file ever disappear from the output of 'splunk list monitor'? (Except for at splunkd restart, of course)

Tags (1)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Yes, the listing is definitely truncated to about 30 files. Deleted files do go away from the list eventually, after at most 24 hours on 4.0 systems (and earlier). They will probably go away sooner on 4.1 (and later).

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

Yes, the listing is definitely truncated to about 30 files. Deleted files do go away from the list eventually, after at most 24 hours on 4.0 systems (and earlier). They will probably go away sooner on 4.1 (and later).

dwaddle
SplunkTrust
SplunkTrust

24 hours almost to the minute...

0 Karma

dwaddle
SplunkTrust
SplunkTrust

This is on a version 4.0.10 system.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Can you specify the version of Splunk where your are monitoring files?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...