<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic new files added to the directory are not getting ingested until you restart Splunk in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/new-files-added-to-the-directory-are-not-getting-ingested-until/m-p/641647#M16198</link>
    <description>&lt;P&gt;We are trying to ingest data from csv files. We have a monitoring stanza in inputs.conf which monitors all csv in a folder.&lt;BR /&gt;Copied one file to that folder and data got ingested. After that tried copying new files to that folder but it stopped ingesting.&lt;BR /&gt;New file is quite different than previous one. Have also tried different index/props, but same issue&lt;BR /&gt;&lt;SPAN&gt;New files added to the directory are not getting ingested until you restart Splunk.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Below is the monitoring stanza and props that we used. The inputs and props are in Heavy Forwarder and it is sending data to indexer cluster.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor:///f1/f2/f3/*.csv]
disabled = 0
index = test_input
sourcetype = test
initCrcLength = 2048
_TCP_ROUTING = test_indexer
crcSalt =&amp;lt;SOURCE&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is the props.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[test]
INDEXED_EXTRACTIONS = csv
CHECK_FOR_HEADER = true
HEADER_FIELD_LINE_NUMBER = 1
TIMESTAMP_FIELDS = mytime
TIME_FORMAT = %Y-%m-%d %H:%M:%S
FIELD_DELIMITER = ,
KV_MODE = none
LINE_BREAKER = ([\r\n]+)
NO_BINARY_CHECK = true
category = Structured
description = Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled = false
pulldown_type = true&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Apr 2023 18:06:24 GMT</pubDate>
    <dc:creator>ankitarath2011</dc:creator>
    <dc:date>2023-04-28T18:06:24Z</dc:date>
    <item>
      <title>new files added to the directory are not getting ingested until you restart Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/new-files-added-to-the-directory-are-not-getting-ingested-until/m-p/641647#M16198</link>
      <description>&lt;P&gt;We are trying to ingest data from csv files. We have a monitoring stanza in inputs.conf which monitors all csv in a folder.&lt;BR /&gt;Copied one file to that folder and data got ingested. After that tried copying new files to that folder but it stopped ingesting.&lt;BR /&gt;New file is quite different than previous one. Have also tried different index/props, but same issue&lt;BR /&gt;&lt;SPAN&gt;New files added to the directory are not getting ingested until you restart Splunk.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Below is the monitoring stanza and props that we used. The inputs and props are in Heavy Forwarder and it is sending data to indexer cluster.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor:///f1/f2/f3/*.csv]
disabled = 0
index = test_input
sourcetype = test
initCrcLength = 2048
_TCP_ROUTING = test_indexer
crcSalt =&amp;lt;SOURCE&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is the props.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[test]
INDEXED_EXTRACTIONS = csv
CHECK_FOR_HEADER = true
HEADER_FIELD_LINE_NUMBER = 1
TIMESTAMP_FIELDS = mytime
TIME_FORMAT = %Y-%m-%d %H:%M:%S
FIELD_DELIMITER = ,
KV_MODE = none
LINE_BREAKER = ([\r\n]+)
NO_BINARY_CHECK = true
category = Structured
description = Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled = false
pulldown_type = true&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 18:06:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/new-files-added-to-the-directory-are-not-getting-ingested-until/m-p/641647#M16198</guid>
      <dc:creator>ankitarath2011</dc:creator>
      <dc:date>2023-04-28T18:06:24Z</dc:date>
    </item>
  </channel>
</rss>

