Monitoring Splunk

index from forwarders every X minutes/hours

jszyba
New Member

Could anybody tell me how to work with the inputs.conf file of a forwarder to set the forwarder to start/stop/index every X amount of time rather than in real time? The cron was mentioned but I'm not so sure how to use it and the documentation is a bit foggy. I basically want the forwarder to start up every X hours and push the latest log file data to the receiver if possible. Thanks all!

Tags (3)
0 Karma

linu1988
Champion

For this you could write a script to stop the splunkforwarder service and start at another point using windows task sceduler(best solution). There is no functionality available in splunk to start or stop the splunk service itself.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...