Monitoring Splunk

Output of 'splunk list monitor'

dwaddle
SplunkTrust
SplunkTrust

Is the output of 'splunk list monitor' clipped at all?

I have a directory with (approx) 50 log files, but the output only shows 30 or so. I know the additional 20 are being indexed, because I have events from them.

Also, does a deleted file ever disappear from the output of 'splunk list monitor'? (Except for at splunkd restart, of course)

Tags (1)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Yes, the listing is definitely truncated to about 30 files. Deleted files do go away from the list eventually, after at most 24 hours on 4.0 systems (and earlier). They will probably go away sooner on 4.1 (and later).

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

Yes, the listing is definitely truncated to about 30 files. Deleted files do go away from the list eventually, after at most 24 hours on 4.0 systems (and earlier). They will probably go away sooner on 4.1 (and later).

dwaddle
SplunkTrust
SplunkTrust

24 hours almost to the minute...

0 Karma

dwaddle
SplunkTrust
SplunkTrust

This is on a version 4.0.10 system.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Can you specify the version of Splunk where your are monitoring files?

0 Karma
Get Updates on the Splunk Community!

Security Professional: Sharpen Your Defenses with These .conf25 Sessions

Sooooooooooo, guess what. .conf25 is almost here, and if you're on the Security Learning Path, this is your ...

First Steps with Splunk SOAR

Our first step was to gather a list of the playbooks we wanted and to sort them by priority.  Once this list ...

How To Build a Self-Service Observability Practice with Splunk Observability Cloud

If you’ve read our previous post on self-service observability, you already know what it is and why it ...