Hi, im currently facing problem where splunk can detect all my files in directory but when doing searching, splunk cannot detect all of it? any ideas?
Hi @aamirulh,
let me understand: do you want to have the list of a files in a folder read by Splunk or a simpli list of them?
In the first case you can list the souces read by Splunk, (if you want the files in "/var/log/" you can run something like this:
your_search source="/var/log/*
| dedup source
| sort source
| table source
if instead you want to list all files id a folder, you have to create a scripted input that lists the files ("ls -al" in Linux and "dir" in Windows) and then display results.
Ciao.
Giuseppe