Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Can move_policy actually move things?

$
0
0
Hi all, I'd like to move a batch input after reading. Except not to /dev/null. The manual is pretty clear: move_policy = sinkhole * IMPORTANT: This setting is required. You *must* include "move_policy = sinkhole" when you define batch inputs. * This setting causes the input to load the file destructively. * Do not use the 'batch' input type for files you do not want to delete after indexing. * The "move_policy" setting exists for historical reasons, but remains as an explicit double check. As an administrator you must very explicitly declare that you want the data in the monitored directory (and its sub-directories) to be deleted after being read and indexed. However, instead of removing, it would be so nice to move it to another location. Anyone knows if this is possible?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>