Monitoring Splunk

Output of 'splunk list monitor'

dwaddle
SplunkTrust
SplunkTrust

Is the output of 'splunk list monitor' clipped at all?

I have a directory with (approx) 50 log files, but the output only shows 30 or so. I know the additional 20 are being indexed, because I have events from them.

Also, does a deleted file ever disappear from the output of 'splunk list monitor'? (Except for at splunkd restart, of course)

Tags (1)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Yes, the listing is definitely truncated to about 30 files. Deleted files do go away from the list eventually, after at most 24 hours on 4.0 systems (and earlier). They will probably go away sooner on 4.1 (and later).

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

Yes, the listing is definitely truncated to about 30 files. Deleted files do go away from the list eventually, after at most 24 hours on 4.0 systems (and earlier). They will probably go away sooner on 4.1 (and later).

dwaddle
SplunkTrust
SplunkTrust

24 hours almost to the minute...

0 Karma

dwaddle
SplunkTrust
SplunkTrust

This is on a version 4.0.10 system.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Can you specify the version of Splunk where your are monitoring files?

0 Karma
Get Updates on the Splunk Community!

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...