All Apps and Add-ons

Deleting a file after calling splunkforwarder add oneshot

othersider2
New Member

After calling splunk/forwarder/bin/splunk add oneshot , is it ok to delete the file I just added, or does the file need to be kept on disk for the forwarder to give it to the splunk enterprise server receiver?

0 Karma

inventsekar
SplunkTrust
SplunkTrust

After calling splunk/forwarder/bin/splunk add oneshot , it is ok to delete the file. maybe, make sure the file got ingested(on splunk gui, you can run the search query for the file)

https://docs.splunk.com/Documentation/Splunk/latest/Data/MonitorfilesanddirectoriesusingtheCLI

Copy the file directly into Splunk. This uploads the file once, but Splunk Enterprise does not continue to monitor it.
You cannot use the oneshot command against a remote Splunk Enterprise instance. You also cannot use the command with either recursive folders or wildcards as a source. Specify the exact source path of the file you want to monitor.

0 Karma

p_gurav
Champion

I am not sure about oneshot, but you can try batch input for your requirement.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...