Hi,
Please let me know how to configure to monitor the directory size change.Actually I am unable to understand which inputs.conf to edit.I have edited the /opt/splunk/etc/system/local/inputs.conf added the following entry
[monitor:///test/]
disabled = false
host = localhost.localdomain
The directory is /test which I want to monitor and restarted the splunk.
I am unable to see any errors on local audit.log.
In my centralized splunk server getting no logs from the mentioned server