Splunk Search

How to check status of specific indexed file using .../services/admin/inputstatus endpoint?

Bhagyashri
Explorer

I have imported "xyz "folder into splunk and after indexing I want to check status of particular abc.txt file from that xyz folder.
how should I do that?

Tags (1)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

There's a decent description of how to use that endpoint here: http://blogs.splunk.com/2011/01/02/did-i-miss-christmas-2/

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

The path is in the result, so you can look for it there.

0 Karma

Bhagyashri
Explorer

Thanks!
Thats correct for all monitored data but I want to work that endpoint for just single file.
example if i provide path of that file from folder with that endpoint then it will give me status like missing|ignored|reading completed .
is that possible?
Because I didn't found detail explanation of that endpoint.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...