How to index zero byte files?
For some reason, a customer created a monitoring file that only contains information on the filename.
Ex:
abx_20160627_exit.ok
I'd like to index the timestamp on the filename and the "type" (exit).
Besides create a script to list and append to another file, can Splunk index this type of data?
Thanks.
Perfect solution. Even better than expected.
You can create a scripted input that does an ls -l
or dir
on the directory/folder.
Thanks for the input. The app above solved the problem.