Getting Data In

How to continuously monitor a file from a shared folder or path?

Shan
Builder

Hai All,

Please help me out to understand. how to continuously monitor a file from a shared folder or path?

Thanks in advance..

adonio
Ultra Champion

in inputs.conf, add [monitor:///full/path/to/file]
you can also use wildcards to constantly monitor many files:
[monitor:///full/path/to/*.log]
here all the files that ends with .log
read all documentation here:
http://docs.splunk.com/Documentation/Splunk/7.1.2/Data/Monitorfilesanddirectorieswithinputs.conf

hope it hepls

0 Karma

renjith_nair
Legend

Its same as splunk file monitors if you are including the absolute path
Ref : https://docs.splunk.com/Documentation/Splunk/7.1.2/Data/Monitorfilesanddirectorieswithinputs.conf
Are you facing any issues?

Happy Splunking!

Shan
Builder

@renjith.nair

I haven't tried it yet.. Just wanna get some idea about how to do it . So i posted a question.

0 Karma

renjith_nair
Legend

Suggest you to try that first and let the community know if you have any issues.

Happy Splunking!
0 Karma

Shan
Builder

@renjith.nair,

No issues.. I'm about to try that one. :-)..

Thanks

0 Karma

ssadanala1
Contributor

Per documentation

[monitor://]
* This directs a file monitor input to watch all files in .
* can be an entire directory or a single file.
* You must specify the input type and then the path, so put three slashes in
your path if you are starting at the root on *nix systems (to include the
slash that indicates an absolute path).

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...