Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

splunk monitor only single file not working

$
0
0

Hi experts,

I have problem in monitoring only file. for example /var/log/messages

I added monitor,

$./splunk add monitor /var/log/messages -index testindex -sourcetype linux_log

But results are not reflecting in splunk search console(WEB GUI)

I even changes file content I retried

It works if I add monitor to /var/log directory

$./splunk add monitor /var/log/ -index testindex -sourcetype linux_log

Is splunk monitoring requires directory?


Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>