<?xml version="1.0" ?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
	<channel>
		<title>Splunk Base : SplunkAdministration : #2831</title>
		<link>http://www.splunk.com/support/forum:SplunkAdministration/2831</link>
		<description></description>
		<pubDate>Sun, 22 Nov 2009 00:52:20 PST</pubDate>
		<lastBuildDate>Sun, 22 Nov 2009 00:52:20 PST</lastBuildDate>
		<language>en-us</language>
		<copyright>http://creativecommons.org/licenses/by-nc-nd/2.5/</copyright>
		<item>
			<title>Splunk to monitor a directory size change(fschange)</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/2831/9055</link>
			<description>&lt;p&gt;Hi,&lt;br /&gt;
Please let me know how to configure to monitor the directory size change.Actually I am unable to understand which inputs.conf to edit.I have edited the /opt/splunk/etc/system/local/inputs.conf added the following entry&lt;/p&gt;

&lt;p&gt;[monitor:///test/]&lt;br /&gt;
disabled = false&lt;br /&gt;
host = localhost.localdomain&lt;/p&gt;

&lt;p&gt;The directory is /test which I want to monitor and restarted the splunk.&lt;br /&gt;
I am unable to see any errors on local audit.log.&lt;/p&gt;

&lt;p&gt;In my centralized splunk server getting no logs from the mentioned server&lt;/p&gt;

</description>
			<pubDate>Sat, 06 Jun 2009 22:47:54 PDT</pubDate>
			<author>subhanjan</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/2831/9055</guid>
		</item>
	</channel>
</rss>
