Getting Data In

How to find status of files being monitored?

wdsjon
Engager

Is there a command or somewhere to look regarding the status of file monitoring? I've set up a UF on an rsyslog machine with tons or currently residing text log files in nested directories that I've created a monitoring stanza for in an inputs.conf. Question - Is there a way from the universal forwarder to see the status of the files it's reading? I've been able to get sort of an idea with lsof , but some of the files are 50GB+. Thanks!

1 Solution

jnussbaum_splun
Splunk Employee
Splunk Employee
$SPLUNK_HOME/bin/splunk _internal call /services/admin/inputstatus/TailingProcessor:FileStatus

should get you done.

View solution in original post

jnussbaum_splun
Splunk Employee
Splunk Employee
$SPLUNK_HOME/bin/splunk _internal call /services/admin/inputstatus/TailingProcessor:FileStatus

should get you done.

robertlynch2020
Motivator

Sorry i am gettign this when i do that

 

bash$ splunk _internal call /services/admin/inputstatus/TailingProcessor:FileStatus
QUERYING: 'https://127.0.0.1:9089/services/admin/inputstatus/TailingProcessor:FileStatus'
This command [GET /services/admin/inputstatus/TailingProcessor:FileStatus] needs splunkd to be up, and splunkd is down.
dell425srv autoengine /dell425srv3/apps/AMBER_FWD/splunkforwarder_AMBER_PSC47_SEC1/splunkforwarder/bin/
bash$

0 Karma

martin_mueller
SplunkTrust
SplunkTrust
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...