Getting Data In

Spotting when a file has been finished indexing?

szabados
Communicator

I have a monitor input, which rarely has new files, and I'd like set up an alert for it. How can I find something about when a file has been finished reading in ?

Tags (3)
0 Karma

MuS
Legend

Hi szabados,

take a look at this great blog post http://blogs.splunk.com/2011/01/02/did-i-miss-christmas-2/ where you learn to use the REST endpoint of the TailingProcessor to show its activities and what files are currently being read.

Hope this helps ...

cheers, MuS

0 Karma

szabados
Communicator

Thanks, but my idea was to set up an alert in splunk, based on the contents of the internal log of the forwarder.

0 Karma

MuS
Legend

You could enable debugging on the TailingProcessor on the forwarder http://docs.splunk.com/Documentation/Splunk/6.3.0/Troubleshooting/Enabledebuglogging and look what is reported in index=_internal or read the docs here http://docs.splunk.com/Documentation/Splunk/latest/Data/Troubleshoottheinputprocess

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...