The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.

Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.

Forums: SplunkAdministration: Splunk to monitor a directory size change(fschange)

Previous Topic: CSV files with headers.  |   Next Topic: Move WMI Input to different Indexes


Posts 1–1 of 1

Hi,
Please let me know how to configure to monitor the directory size change.Actually I am unable to understand which inputs.conf to edit.I have edited the /opt/splunk/etc/system/local/inputs.conf added the following entry

[monitor:///test/]
disabled = false
host = localhost.localdomain

The directory is /test which I want to monitor and restarted the splunk.
I am unable to see any errors on local audit.log.

In my centralized splunk server getting no logs from the mentioned server