Getting Data In

Can I monitor a file with extension .splunk?

btawiah
Explorer

Trying to monitor a file that ends with .splunk but for some reason splunk will not index it. Only when I change the extension to .txt, it ingests. Any reasons why this is happening?

Thanks

0 Karma
1 Solution

cvssravan
Path Finder

@btawiah
This is the reason:

Files with a .splunk filename extension are also not monitored, because files with that extension contain Splunk metadata. If you need to index files with a .splunk extension, use the add oneshot CLI command.

You can read more here:
https://docs.splunk.com/Documentation/Splunk/7.2.4/Data/Monitorfilesanddirectories

View solution in original post

cvssravan
Path Finder

@btawiah
This is the reason:

Files with a .splunk filename extension are also not monitored, because files with that extension contain Splunk metadata. If you need to index files with a .splunk extension, use the add oneshot CLI command.

You can read more here:
https://docs.splunk.com/Documentation/Splunk/7.2.4/Data/Monitorfilesanddirectories

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...