Getting Data In

active-only/eatonlylivefiles in Splunk 4.3

matthewpowell
Engager

The "active-only" feature doesn't seem to work in Splunk 4.3:

# splunk add monitor /var/log/messages -active-only true
In handler 'monitor': Argument "eatonlylivefiles" is not supported by this handler.

It's still listed as a feature in "splunk help add" and at http://docs.splunk.com/Documentation/Splunk/latest/Data/MonitorfilesanddirectoriesusingtheCLI.

Has the feature been removed (and if so, is there a reason why it's no longer useful)? Or is this a bug?

Tags (3)
1 Solution

hexx
Splunk Employee
Splunk Employee

As you found out, this option has been taken out of the code base as of Splunk 4.3. The references to it in the CLI documentation and help have been left behind by mistake. I've just removed the reference in the CLI documentation and it will be gone from the CLI help in Splunk 4.3.1.

View solution in original post

hexx
Splunk Employee
Splunk Employee

As you found out, this option has been taken out of the code base as of Splunk 4.3. The references to it in the CLI documentation and help have been left behind by mistake. I've just removed the reference in the CLI documentation and it will be gone from the CLI help in Splunk 4.3.1.

hexx
Splunk Employee
Splunk Employee

This feature has been removed as of Splunk 4.1 because its implementation did not yield satisfactory results and seemed redundant with the improved tailing processor that was introduced with that version.

matthewpowell
Engager

Thanks for the answer. Out of curiosity, do you know why it was removed? Were there problems with the feature, or was it just not all that useful in the first place?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...