This documentation applies to the following versions of Splunk: 4.0 , 4.0.1 , 4.0.2 , 4.0.3 , 4.0.4 , 4.0.5 , 4.0.6 , 4.0.7 , 4.0.8 , 4.0.9 , 4.0.10
Processes the given file as if it were indexed.
file filename
If filename is a file the file command will read the file as if it was indexed in splunk, if filename is a directory file will display the list of files in that directory with the option of adding those to the inputs.
Example 1: Display events from the file "messages.1" as if the events were indexed in Splunk.