Splunk Search

Why is splunk not detecting All Files during search?

aamirulh
New Member

aamirulh_0-1654575502949.png

Hi, im currently facing problem where splunk can detect all my files in directory but when doing searching, splunk cannot detect all of it? any ideas?

aamirulh_0-1654575603692.png

 

 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aamirulh,

let me understand: do you want to have the list of a files in a folder read by Splunk or a simpli list of them?

In the first case you can list the souces read by Splunk, (if you want the files in "/var/log/" you can run something like this:

your_search source="/var/log/*
| dedup source
| sort source
| table source

 if instead you want to list all files id a folder, you have to create a scripted input that lists the files ("ls -al" in Linux and "dir" in Windows) and then display results.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...