All Apps and Add-ons

Sinkhole Configuration

bcruz
Engager

I modified the inputs.conf on my /system/local/ to add batch stanza with sinkhole hoping that files going to that folder will be consumed destructively. Files are getting indexed, however they are not getting deleted.

Anything that i have missed?

inputs.conf

[batch:///{path}]
move_policy = sinkhole

Tags (1)

RicoSuave
Builder

Sounds like this could be a permissions issue. Your splunkd.log should give you more insight.

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...