Splunk Search

Read a file using Splunk without indexing it?

the_wolverine
Champion

I thought there was a way (command) that would users with the right permissions to read a file on the Splunk filesystem without indexing that file. Would someone point me to the documentation (if it exists)?

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Well that would be a rather dangerous thing, security-wise. It doesn't exist. The closest things are "inputcsv" and "inputlookup". You could if you really wanted write a custom search command that did what you want.

the_wolverine
Champion

Maybe I'm wrong but, secure or not, I thought it existed, at least maybe in a previous version.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...