Hi ,
I saw this search command in "File Monitor Inputs" dashboard in SoS App
this command can get some special information about splunk monitor file , for example : splunk detect a file which size is zero , seek pointer position is zero , status is "finished reading" , I need these kind of information
anyone know how to get theose message using search command ?
I tried to study the source code of "tpstatusquery" command but it is too difficult for me
thanks
Note: replace "yourhosthere" with the actual case-sensitive host name.
| tpstatusquery targetserver="yourhosthere" namespace="system" owner="nobody" admin/inputstatus/TailingProcessor:FileStatus | table *