Hi
I want to monitor a log file in "C:\Windows\Logs\CBS.log" in an SPL command
Is it possible with wineventlog or with anotherway please?
regards
hi
no not to ingest directly
i have to check the size file of CBS.log" in an SPL command on many machines
if i see that this file is > to 1 GO i have to receive an email
what do you thing about this code?
source="C:\Windows\Logs\CBS.log" | eval esize=len(_raw) | stats sum(esize) by sourcetype
or do i need File/Directory Information Input Add-on?
Thanks
Hi,
If I understand your question - you want to ingest the file CBS.log .
If that is the case you can follow the instructions available in below Doc.
https://docs.splunk.com/Documentation/Splunk/7.0.2/Data/MonitorfilesanddirectorieswithSplunkWeb
If not can you elaborate your question?
Thanks | RD
