Monitoring Splunk

Output of 'splunk list monitor'

dwaddle
SplunkTrust
SplunkTrust

Is the output of 'splunk list monitor' clipped at all?

I have a directory with (approx) 50 log files, but the output only shows 30 or so. I know the additional 20 are being indexed, because I have events from them.

Also, does a deleted file ever disappear from the output of 'splunk list monitor'? (Except for at splunkd restart, of course)

Tags (1)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Yes, the listing is definitely truncated to about 30 files. Deleted files do go away from the list eventually, after at most 24 hours on 4.0 systems (and earlier). They will probably go away sooner on 4.1 (and later).

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

Yes, the listing is definitely truncated to about 30 files. Deleted files do go away from the list eventually, after at most 24 hours on 4.0 systems (and earlier). They will probably go away sooner on 4.1 (and later).

dwaddle
SplunkTrust
SplunkTrust

24 hours almost to the minute...

0 Karma

dwaddle
SplunkTrust
SplunkTrust

This is on a version 4.0.10 system.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Can you specify the version of Splunk where your are monitoring files?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...