Getting Data In

Monitoring files from multiple inputs

anna_kendrik
Engager

How can I set my monitor in inputs.conf so that both of these directories are monitored-
1./var/lib/usr
2. /var/lib/newuser/usr

If I do [monitor:///var/lib/.../usr/] - will that work for both? Or will that assume that there is at least one subdirectory between "lib" and "usr"

Thanks in advance!

Tags (2)
0 Karma

Gilberto_Castil
Splunk Employee
Splunk Employee

In general terms these two directories separate entities. While they are in the same tree, these have different inodes and you can monitor each individually. So, the answer to your question is to create two (2) separate entries in inputs.conf.

[monitor:///var/lib/usr]
sourcetype = answers-1370379558 

[monitor:///var/lib/newuser/usr]
sourcetype = answers-1370379591 

Is there more to your question?

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...