Splunk Search

Why is splunk not detecting All Files during search?

aamirulh
New Member

aamirulh_0-1654575502949.png

Hi, im currently facing problem where splunk can detect all my files in directory but when doing searching, splunk cannot detect all of it? any ideas?

aamirulh_0-1654575603692.png

 

 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aamirulh,

let me understand: do you want to have the list of a files in a folder read by Splunk or a simpli list of them?

In the first case you can list the souces read by Splunk, (if you want the files in "/var/log/" you can run something like this:

your_search source="/var/log/*
| dedup source
| sort source
| table source

 if instead you want to list all files id a folder, you have to create a scripted input that lists the files ("ls -al" in Linux and "dir" in Windows) and then display results.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...