<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitoring of remote directory in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Monitoring-of-remote-directory/m-p/185927#M6933</link>
    <description>&lt;P&gt;To be more clear i shall say this way E:\Splunk has 2 folders ftplogs and ncpi. ftplogs has 5 more folders in it say a,b,c,d,e. the folder a has 10 log files in it with names SystemOut_14.03.2014_18.07.01, SystemOut_14.03.2014_18.07.02 like that ....till 18.07.10. But from SPLUNK machine I could just view only the first log file but not the rest, though I gave monitor=[E:\Splunk] under inputs.conf file&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 16:07:20 GMT</pubDate>
    <dc:creator>sushma7</dc:creator>
    <dc:date>2020-09-28T16:07:20Z</dc:date>
    <item>
      <title>Monitoring of remote directory</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Monitoring-of-remote-directory/m-p/185925#M6931</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;I have installed Universal forwarder on one of the box that I need to monitor.In that machine I want to monitor a particular folder under E drive, say E:\Splunk. The splunk folder has inturn two more directories ftplogs and NPCI. The NPCI inturn has set of directories which inturn has some logs in it. Splunk can monitor only few directories under NPCI but not all, why is it happening so? Need your suggestion.&lt;/P&gt;

&lt;P&gt;Thanks in advance for your help!&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Sushma.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2014 10:33:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Monitoring-of-remote-directory/m-p/185925#M6931</guid>
      <dc:creator>sushma7</dc:creator>
      <dc:date>2014-03-13T10:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of remote directory</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Monitoring-of-remote-directory/m-p/185926#M6932</link>
      <description>&lt;P&gt;Impossible to say without more details. General troubleshooting tips: check splunkd.log for errors, use amrit's script at &lt;A href="http://blogs.splunk.com/2011/01/02/did-i-miss-christmas-2/"&gt;http://blogs.splunk.com/2011/01/02/did-i-miss-christmas-2/&lt;/A&gt; to see which file inputs Splunk has and what status they have.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2014 10:55:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Monitoring-of-remote-directory/m-p/185926#M6932</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2014-03-13T10:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of remote directory</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Monitoring-of-remote-directory/m-p/185927#M6933</link>
      <description>&lt;P&gt;To be more clear i shall say this way E:\Splunk has 2 folders ftplogs and ncpi. ftplogs has 5 more folders in it say a,b,c,d,e. the folder a has 10 log files in it with names SystemOut_14.03.2014_18.07.01, SystemOut_14.03.2014_18.07.02 like that ....till 18.07.10. But from SPLUNK machine I could just view only the first log file but not the rest, though I gave monitor=[E:\Splunk] under inputs.conf file&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:07:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Monitoring-of-remote-directory/m-p/185927#M6933</guid>
      <dc:creator>sushma7</dc:creator>
      <dc:date>2020-09-28T16:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of remote directory</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Monitoring-of-remote-directory/m-p/185928#M6934</link>
      <description>&lt;P&gt;Kindly someone help me on this&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2014 05:27:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Monitoring-of-remote-directory/m-p/185928#M6934</guid>
      <dc:creator>sushma7</dc:creator>
      <dc:date>2014-03-14T05:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of remote directory</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Monitoring-of-remote-directory/m-p/185929#M6935</link>
      <description>&lt;P&gt;Have a look at the troubleshooting tips I gave you.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2014 06:05:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Monitoring-of-remote-directory/m-p/185929#M6935</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2014-03-14T06:05:17Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of remote directory</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Monitoring-of-remote-directory/m-p/185930#M6936</link>
      <description>&lt;P&gt;Under inputs.conf file i just enetered [monitor:///E:Splunk]&lt;BR /&gt;
disabled =false&lt;BR /&gt;
recursive = true&lt;BR /&gt;
Is thereanything more I need to enter?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2014 06:14:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Monitoring-of-remote-directory/m-p/185930#M6936</guid>
      <dc:creator>sushma7</dc:creator>
      <dc:date>2014-03-14T06:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of remote directory</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Monitoring-of-remote-directory/m-p/185931#M6937</link>
      <description>&lt;P&gt;Please &lt;STRONG&gt;read the troubleshooting tips&lt;/STRONG&gt; I gave you.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2014 08:46:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Monitoring-of-remote-directory/m-p/185931#M6937</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2014-03-14T08:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of remote directory</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Monitoring-of-remote-directory/m-p/185932#M6938</link>
      <description>&lt;P&gt;It is likely that the files contain identical content in important sections and have the same CRC so are being interpreted as the same file (only forward it once):&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/Howlogfilerotationishandled"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/Howlogfilerotationishandled&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You can Salt with the filename with &lt;CODE&gt;crcSalt=&lt;/CODE&gt; so this will not happen.&lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2015 04:04:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Monitoring-of-remote-directory/m-p/185932#M6938</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-05-25T04:04:39Z</dc:date>
    </item>
  </channel>
</rss>

