<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Monitoring a file in $SPLUNKHOME/etc/apps/search/lookups in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-file-in-SPLUNKHOME-etc-apps-search-lookups/m-p/21451#M3186</link>
    <description>&lt;P&gt;Does splunk read $SPLUNKHOME/etc/apps/search/lookups in a special manner?  I placed a csv file in that directory of a search head to be monitored and it seems like it is not being indexed, or at least it's not searchable.  Using it as an inputlookup works though.  I want to monitor that file and use it in a form search, an inventory search.  &lt;/P&gt;

&lt;P&gt;Checked /var/log/splunk/splunkd.log, below is the only log found on the directory/path where the file is:&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;INFO TailingProcessor - Parsing configuration stanza: monitor:///splunksearches/SH/etc/apps/search/lookups/filename.csv&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;INFO  TailingProcessor - Adding watch on path:///splunksearches/SH/etc/apps/search/lookups/filename.csv&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Aug 2013 04:01:07 GMT</pubDate>
    <dc:creator>mcm10285</dc:creator>
    <dc:date>2013-08-01T04:01:07Z</dc:date>
    <item>
      <title>Monitoring a file in $SPLUNKHOME/etc/apps/search/lookups</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-file-in-SPLUNKHOME-etc-apps-search-lookups/m-p/21451#M3186</link>
      <description>&lt;P&gt;Does splunk read $SPLUNKHOME/etc/apps/search/lookups in a special manner?  I placed a csv file in that directory of a search head to be monitored and it seems like it is not being indexed, or at least it's not searchable.  Using it as an inputlookup works though.  I want to monitor that file and use it in a form search, an inventory search.  &lt;/P&gt;

&lt;P&gt;Checked /var/log/splunk/splunkd.log, below is the only log found on the directory/path where the file is:&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;INFO TailingProcessor - Parsing configuration stanza: monitor:///splunksearches/SH/etc/apps/search/lookups/filename.csv&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;INFO  TailingProcessor - Adding watch on path:///splunksearches/SH/etc/apps/search/lookups/filename.csv&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2013 04:01:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-file-in-SPLUNKHOME-etc-apps-search-lookups/m-p/21451#M3186</guid>
      <dc:creator>mcm10285</dc:creator>
      <dc:date>2013-08-01T04:01:07Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a file in $SPLUNKHOME/etc/apps/search/lookups</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-file-in-SPLUNKHOME-etc-apps-search-lookups/m-p/21452#M3187</link>
      <description>&lt;P&gt;Why would you index a lookup? If you want to start searches with that data, just use &lt;CODE&gt;inputlookup&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2013 06:34:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-file-in-SPLUNKHOME-etc-apps-search-lookups/m-p/21452#M3187</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-08-01T06:34:35Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a file in $SPLUNKHOME/etc/apps/search/lookups</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-file-in-SPLUNKHOME-etc-apps-search-lookups/m-p/21453#M3188</link>
      <description>&lt;P&gt;I don't.  I just placed a file in the lookups folder and I want to index that.  &lt;/P&gt;

&lt;P&gt;Input lookup needs a search against it.  I need to search on the file itself.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2013 08:44:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-file-in-SPLUNKHOME-etc-apps-search-lookups/m-p/21453#M3188</guid>
      <dc:creator>mcm10285</dc:creator>
      <dc:date>2013-08-01T08:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a file in $SPLUNKHOME/etc/apps/search/lookups</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-file-in-SPLUNKHOME-etc-apps-search-lookups/m-p/21454#M3189</link>
      <description>&lt;P&gt;Start your search with &lt;CODE&gt;inputlookup&lt;/CODE&gt;, that'll give you the file in Splunk to continue your search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| inputlookup file_name | search something or other
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 01 Aug 2013 11:00:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-file-in-SPLUNKHOME-etc-apps-search-lookups/m-p/21454#M3189</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-08-01T11:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a file in $SPLUNKHOME/etc/apps/search/lookups</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-file-in-SPLUNKHOME-etc-apps-search-lookups/m-p/21455#M3190</link>
      <description>&lt;P&gt;Using tail for a one time file index routine is not the best way to go about it.&lt;BR /&gt;
Try it from the commandline - see this post&lt;BR /&gt;
splunk-base.splunk.com/answers/6922/how-to-ask-splunk-to-index-a-file-using-the-cli&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2013 13:30:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-file-in-SPLUNKHOME-etc-apps-search-lookups/m-p/21455#M3190</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-08-01T13:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a file in $SPLUNKHOME/etc/apps/search/lookups</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-file-in-SPLUNKHOME-etc-apps-search-lookups/m-p/21456#M3191</link>
      <description>&lt;P&gt;tried the CLI and returned the message below&lt;/P&gt;

&lt;P&gt;In handler 'monitor': Cannot create another input with the name "/splunksearches/SH/etc/apps/search/lookups/IP_Blocklist.csv", one already exists.&lt;/P&gt;

&lt;P&gt;However, when I checked, the data is already indexed.  Wonder how long it took.&lt;/P&gt;

&lt;P&gt;Thanks for the suggestions anyway.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2013 03:09:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-file-in-SPLUNKHOME-etc-apps-search-lookups/m-p/21456#M3191</guid>
      <dc:creator>mcm10285</dc:creator>
      <dc:date>2013-08-02T03:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a file in $SPLUNKHOME/etc/apps/search/lookups</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-file-in-SPLUNKHOME-etc-apps-search-lookups/m-p/21457#M3192</link>
      <description>&lt;P&gt;somewhow this just worked..might have been a delayed indexing...&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2013 06:32:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-file-in-SPLUNKHOME-etc-apps-search-lookups/m-p/21457#M3192</guid>
      <dc:creator>mcm10285</dc:creator>
      <dc:date>2013-09-11T06:32:59Z</dc:date>
    </item>
  </channel>
</rss>

