<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File and Dir File Monitoring not working in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/File-and-Dir-File-Monitoring-not-working/m-p/631731#M108268</link>
    <description>&lt;P&gt;I have solved this sort of.. for some reason the new index I created wont take data. Once I re-did all this and pointed it to an older index it started to work.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Feb 2023 15:09:20 GMT</pubDate>
    <dc:creator>DesertSocBum</dc:creator>
    <dc:date>2023-02-21T15:09:20Z</dc:date>
    <item>
      <title>File and Dir File Monitoring not working?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/File-and-Dir-File-Monitoring-not-working/m-p/631042#M108169</link>
      <description>&lt;P&gt;Setup an app folder on my search head (clustered with indexers and HECS)&amp;nbsp; "TA-Whatever"&amp;nbsp; from the app builder. Dropped a&amp;nbsp; py script in the default folder inside TA-whatever that gens a json file that gets dropped in the parent app TA-whatever folder.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When going to the add data, file and directory menu, I wen thru the server file system drop downs and selected the&amp;nbsp; json file and on the 2nd page where you select the sourcetype it sees the&amp;nbsp; json data.&amp;nbsp; After I select my index, source type and all that, finish, restart Splunk, and search the index,&amp;nbsp; I see nothing, no data is there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have rebuilt the app several times as the Splunk user,&amp;nbsp; as root.&amp;nbsp; chmod everything to 777. rebuild source types and index's. did props conf, treid with no entry in props.&amp;nbsp; added inputs conf to the local app folder, tried with no input.conf in the ta-whatever local folder,&amp;nbsp; also added a monitor to the global inputs.conf in etc/sys/local and still no dice.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;here is my input.conf that i tried in global and the local app directory:&lt;BR /&gt;&lt;BR /&gt;[monitor://tmp/felt.json]&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = googlepyscript&lt;BR /&gt;sourcetype = googlepy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also tried:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[monitor:///tmp/felt.json]&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = googlepyscript&lt;BR /&gt;sourcetype = googlepy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No matter what I do the index is not getting data. I have tried it with the build in _json sourcetype and created my own and no data goes to the index after I finish the wizard.&amp;nbsp; &amp;nbsp;Any input is welcomed at this point as I have been going at it for several days. Thanks!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 15:10:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/File-and-Dir-File-Monitoring-not-working/m-p/631042#M108169</guid>
      <dc:creator>DesertSocBum</dc:creator>
      <dc:date>2023-02-21T15:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: File and Dir File Monitoring not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/File-and-Dir-File-Monitoring-not-working/m-p/631731#M108268</link>
      <description>&lt;P&gt;I have solved this sort of.. for some reason the new index I created wont take data. Once I re-did all this and pointed it to an older index it started to work.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 15:09:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/File-and-Dir-File-Monitoring-not-working/m-p/631731#M108268</guid>
      <dc:creator>DesertSocBum</dc:creator>
      <dc:date>2023-02-21T15:09:20Z</dc:date>
    </item>
  </channel>
</rss>

