Monitor Splunk Enterprise files and directories with the CLI
On Splunk Enterprise installations, you can monitor files and directories using the command line interface (CLI). To use the CLI, navigate to the
$SPLUNK_HOME/bin/ directory from a command prompt or shell, and use the
splunk command in that directory.
The CLI has built-in help. Access the main CLI help by typing
splunk help. Individual commands have their own help pages as well. Access that help by typing
splunk help <command>.
CLI commands for input configuration
The following commands are available for input configuration using the CLI:
||Monitor inputs from |
||Edit a previously added monitor input for |
||Remove a previously added monitor input for |
||List the currently configured monitor inputs.|
||Copy the source file directly into Splunk Enterprise. This uploads the file once, but Splunk Enterprise does not continue to monitor it.
||Copy the source file directly into Splunk Enterprise using the sinkhole directory. Similar to the |
CLI parameters for input configuration
Change the configuration of each data input type by setting additional parameters. To set parameters, use the syntax
You can set only one
-hostsegmentnum per command.
||Yes||Provide the path to the file or directory being monitored and uploaded for new input.
||No||Provide a |
||No||Provide the destination index for events from the input source.|
||No||Provide a host name to set as the host field value for events from the input source.
||No||Provide a regular expression to use to extract the host field value from the source key.
||No||An integer, which determines what "/" separated segment of the path to set as the host field value. If set to 3, for example, the third segment of the path is used.
||No||Provide a value for the |
||No||Set to true or false. Default is false.
This parameter is not available for the
Example 1: Monitor files in a directory
The following example shows how to monitor files in
/var/log/ as a data input:
./splunk add monitor /var/log/
Example 2: Monitor windowsupdate.log
The following example shows how to monitor the Windows Update log file where Windows logs automatic updates, sending the data to an index called
C:\Windows\windowsupdate.log as a data input:
splunk add monitor c:\Windows\windowsupdate.log -index newindex
Example 3: Monitor Internet Information Server (IIS) logging
This example shows how to monitor the default location for Windows IIS logging.
C:\windows\system32\LogFiles\W3SVC as a data input:
./splunk add monitor c:\windows\system32\LogFiles\W3SVC
Example 4: Upload a file
This example shows how to upload a file into Splunk Enterprise. Splunk Enterprise consumes the file only once. It does not monitor it continuously.
/var/log/applog on Unix or
C:\Program Files\AppLog\log.txt on Windows directly into Splunk Enterprise with the
add oneshot command:
You can also upload a file through the sinkhole directory with the
The result is the same with either command.
Monitor files and directories with Splunk Web
Monitor files and directories with inputs.conf
This documentation applies to the following versions of Splunk® Enterprise: 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11, 6.5.0, 6.5.1, 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.5.10, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 6.6.6, 6.6.7, 6.6.8, 6.6.9, 6.6.10, 6.6.11, 6.6.12, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.8, 7.0.10, 7.0.11, 7.0.13, 7.1.0, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.1.9, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.2.9, 7.2.10, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 7.3.9, 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.0.7, 8.0.8, 8.0.9, 8.0.10, 8.1.0, 8.1.1, 8.1.2, 8.1.3, 8.1.4, 8.1.5, 8.1.6, 8.1.7, 8.2.0, 8.2.1, 8.2.2, 8.2.3, 7.0.7, 7.0.9, 7.1.1, 7.1.10