Monitoring Splunk

index from forwarders every X minutes/hours

jszyba
New Member

Could anybody tell me how to work with the inputs.conf file of a forwarder to set the forwarder to start/stop/index every X amount of time rather than in real time? The cron was mentioned but I'm not so sure how to use it and the documentation is a bit foggy. I basically want the forwarder to start up every X hours and push the latest log file data to the receiver if possible. Thanks all!

Tags (3)
0 Karma

linu1988
Champion

For this you could write a script to stop the splunkforwarder service and start at another point using windows task sceduler(best solution). There is no functionality available in splunk to start or stop the splunk service itself.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...