Hi,
we have got a inputs.conf with :
[monitor:///home/.../.bash_history]
disabled = 0
crcSalt = <SOURCE>
whitelist = \.bash_history$
Just to monitor the .bash_history file. But when i look at "./splunk list monitor" it list every file in the /home/... folders. Besides that.. the splunkd process just uses much cpu. (no wonder with so many files in the "list monitor" i think).
Why is the splunkd on the universal forwarder monitoring every file in the /home/... folders while all he has to do is check .bash_history? What am i doing wrong with this input?
thanks in advance
Jari
p.s. Splunk version 8.1.3