Monitoring Splunk

Output of 'splunk list monitor'

dwaddle
SplunkTrust
SplunkTrust

Is the output of 'splunk list monitor' clipped at all?

I have a directory with (approx) 50 log files, but the output only shows 30 or so. I know the additional 20 are being indexed, because I have events from them.

Also, does a deleted file ever disappear from the output of 'splunk list monitor'? (Except for at splunkd restart, of course)

Tags (1)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Yes, the listing is definitely truncated to about 30 files. Deleted files do go away from the list eventually, after at most 24 hours on 4.0 systems (and earlier). They will probably go away sooner on 4.1 (and later).

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

Yes, the listing is definitely truncated to about 30 files. Deleted files do go away from the list eventually, after at most 24 hours on 4.0 systems (and earlier). They will probably go away sooner on 4.1 (and later).

dwaddle
SplunkTrust
SplunkTrust

24 hours almost to the minute...

0 Karma

dwaddle
SplunkTrust
SplunkTrust

This is on a version 4.0.10 system.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Can you specify the version of Splunk where your are monitoring files?

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...