<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to monitoring same file. it is different location file. in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/how-to-monitoring-same-file-it-is-different-location-file/m-p/517606#M3219</link>
    <description>&lt;P&gt;hello&amp;nbsp;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/64317" target="_blank" rel="noopener"&gt;@rnowitzki&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you means that i can same file monitoring at my setting?&lt;/P&gt;&lt;P&gt;i testing but, o&lt;SPAN&gt;nly some data is monitored.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;ex) host : TEST1, TEST3&lt;/P&gt;&lt;P&gt;It also attempted to set up at host_segment = 4.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The result was that the host name was a file name. not folder name&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;is it ok. host_segment = 3&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;my problem is that some of the same files in other folders are monitored. why???? T_T&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;ty so much.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Sep 2020 06:52:23 GMT</pubDate>
    <dc:creator>YUNHYEONG</dc:creator>
    <dc:date>2020-09-03T06:52:23Z</dc:date>
    <item>
      <title>how to monitoring same file. it is different location file.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/how-to-monitoring-same-file-it-is-different-location-file/m-p/517421#M3204</link>
      <description>&lt;P&gt;hello splunker.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I would like to monitor the same file in another folder as below.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;each host is a folder name.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;it is works in one app.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The file names in the folder may be the same or different.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="저장.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10605i60568F69F4E40FF0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="저장.png" alt="저장.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;&lt;FONT&gt;my setting : input.conf&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;[monitor://D:\Splunk\Check\TEST*\*.csv]&lt;BR /&gt;disabled = false&lt;BR /&gt;host_regex =&lt;BR /&gt;index = test&lt;BR /&gt;host =&lt;BR /&gt;host_segment = 3&lt;BR /&gt;sourcetype = testcheck&lt;BR /&gt;crcSalt = &amp;lt;&amp;lt;SOURCE&amp;gt;&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;ty help me&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2020 07:59:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/how-to-monitoring-same-file-it-is-different-location-file/m-p/517421#M3204</guid>
      <dc:creator>YUNHYEONG</dc:creator>
      <dc:date>2020-09-02T07:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: how to monitoring same file. it is different location file.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/how-to-monitoring-same-file-it-is-different-location-file/m-p/517443#M3205</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/116818"&gt;@YUNHYEONG&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;There is one issue with the host segment, let me quote the &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/Admin/Inputsconf" target="_self"&gt;Documentation&lt;/A&gt;:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;PRE&gt;* On Windows machines, &lt;STRONG&gt;the drive letter&lt;/STRONG&gt; and colon before the backslash &lt;STRONG&gt;count
  as one segment&lt;/STRONG&gt;.
    * For example, if you set host_segment=3 and the monitor path is
      D:\logs\servers\host01, Splunk software sets the host as "servers" because
      that is the third segment.&lt;/PRE&gt;&lt;P&gt;So it would need to be &lt;EM&gt;host_segment = 4&lt;/EM&gt; in your case.&lt;BR /&gt;&lt;BR /&gt;Other than that I don't see a problem with the settings.&lt;BR /&gt;What does not work for you, besides the host assignment?&lt;BR /&gt;&lt;BR /&gt;BR&lt;BR /&gt;Ralph&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2020 09:27:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/how-to-monitoring-same-file-it-is-different-location-file/m-p/517443#M3205</guid>
      <dc:creator>rnowitzki</dc:creator>
      <dc:date>2020-09-02T09:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: how to monitoring same file. it is different location file.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/how-to-monitoring-same-file-it-is-different-location-file/m-p/517606#M3219</link>
      <description>&lt;P&gt;hello&amp;nbsp;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/64317" target="_blank" rel="noopener"&gt;@rnowitzki&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you means that i can same file monitoring at my setting?&lt;/P&gt;&lt;P&gt;i testing but, o&lt;SPAN&gt;nly some data is monitored.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;ex) host : TEST1, TEST3&lt;/P&gt;&lt;P&gt;It also attempted to set up at host_segment = 4.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The result was that the host name was a file name. not folder name&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;is it ok. host_segment = 3&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;my problem is that some of the same files in other folders are monitored. why???? T_T&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;ty so much.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 06:52:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/how-to-monitoring-same-file-it-is-different-location-file/m-p/517606#M3219</guid>
      <dc:creator>YUNHYEONG</dc:creator>
      <dc:date>2020-09-03T06:52:23Z</dc:date>
    </item>
    <item>
      <title>Re: how to monitoring same file. it is different location file.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/how-to-monitoring-same-file-it-is-different-location-file/m-p/517659#M3225</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/116818"&gt;@YUNHYEONG&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Yes, it should ingest all the files matching the path pattern.&lt;BR /&gt;Can you share some examples of files that are not getting indexed? (full path and filename).&lt;BR /&gt;&lt;BR /&gt;Also, is the problem that you are monitoring too few files or too many files?&amp;nbsp;&lt;BR /&gt;=&amp;gt; Because you wrote "&lt;SPAN&gt;o&lt;/SPAN&gt;&lt;SPAN&gt;nly some data is monitored." vs. "some of the same files in other folders are monitored"...&lt;BR /&gt;&lt;BR /&gt;BR&lt;BR /&gt;Ralph&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 07:41:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/how-to-monitoring-same-file-it-is-different-location-file/m-p/517659#M3225</guid>
      <dc:creator>rnowitzki</dc:creator>
      <dc:date>2020-09-03T07:41:11Z</dc:date>
    </item>
  </channel>
</rss>

