Splunk Search

Why is splunk not detecting All Files during search?

aamirulh
New Member

aamirulh_0-1654575502949.png

Hi, im currently facing problem where splunk can detect all my files in directory but when doing searching, splunk cannot detect all of it? any ideas?

aamirulh_0-1654575603692.png

 

 

Labels (1)
0 Karma

gcusello
Esteemed Legend

Hi @aamirulh,

let me understand: do you want to have the list of a files in a folder read by Splunk or a simpli list of them?

In the first case you can list the souces read by Splunk, (if you want the files in "/var/log/" you can run something like this:

your_search source="/var/log/*
| dedup source
| sort source
| table source

 if instead you want to list all files id a folder, you have to create a scripted input that lists the files ("ls -al" in Linux and "dir" in Windows) and then display results.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...