Splunk Search

How to check status of specific indexed file using .../services/admin/inputstatus endpoint?

Bhagyashri
Explorer

I have imported "xyz "folder into splunk and after indexing I want to check status of particular abc.txt file from that xyz folder.
how should I do that?

Tags (1)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

There's a decent description of how to use that endpoint here: http://blogs.splunk.com/2011/01/02/did-i-miss-christmas-2/

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

The path is in the result, so you can look for it there.

0 Karma

Bhagyashri
Explorer

Thanks!
Thats correct for all monitored data but I want to work that endpoint for just single file.
example if i provide path of that file from folder with that endpoint then it will give me status like missing|ignored|reading completed .
is that possible?
Because I didn't found detail explanation of that endpoint.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...