Monitoring Splunk

index from forwarders every X minutes/hours

jszyba
New Member

Could anybody tell me how to work with the inputs.conf file of a forwarder to set the forwarder to start/stop/index every X amount of time rather than in real time? The cron was mentioned but I'm not so sure how to use it and the documentation is a bit foggy. I basically want the forwarder to start up every X hours and push the latest log file data to the receiver if possible. Thanks all!

Tags (3)
0 Karma

linu1988
Champion

For this you could write a script to stop the splunkforwarder service and start at another point using windows task sceduler(best solution). There is no functionality available in splunk to start or stop the splunk service itself.

0 Karma
Get Updates on the Splunk Community!

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...

Splunkbase | Splunk Dashboard Examples App for SimpleXML End of Life

The Splunk Dashboard Examples App for SimpleXML will reach end of support on Dec 19, 2024, after which no new ...

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...