<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165200#M33510</link>
    <description>&lt;P&gt;ok&lt;BR /&gt;
 1. click on  &lt;STRONG&gt;add data&lt;/STRONG&gt;&lt;BR /&gt;
 2. click on &lt;STRONG&gt;monitor&lt;/STRONG&gt;&lt;BR /&gt;
 3. &lt;STRONG&gt;files &amp;amp; directories&lt;/STRONG&gt;&lt;BR /&gt;
 4. give the path and then click on continuously monitor&lt;/P&gt;</description>
    <pubDate>Fri, 24 Apr 2015 14:40:59 GMT</pubDate>
    <dc:creator>NOUMSSI</dc:creator>
    <dc:date>2015-04-24T14:40:59Z</dc:date>
    <item>
      <title>Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165192#M33502</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;

&lt;P&gt;I'm looking to monitor some files locally on the Splunk instance, and I am able to add them as data inputs. However, this monitoring does not seem to be continuous; it logs those files once and then doesn't continue to monitor them even as data is added. Am I doing something wrong? How do I get these to monitor changes to the files? Thanks very much! &lt;/P&gt;

&lt;P&gt;This is a Splunk for Windows instance running on Windows 2008 R2. &lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2015 14:00:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165192#M33502</guid>
      <dc:creator>ceichhorn</dc:creator>
      <dc:date>2015-04-24T14:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165193#M33503</link>
      <description>&lt;P&gt;hi,&lt;BR /&gt;
these are the windows files?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2015 14:05:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165193#M33503</guid>
      <dc:creator>gyslainlatsa</dc:creator>
      <dc:date>2015-04-24T14:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165194#M33504</link>
      <description>&lt;P&gt;Yes, I'm sorry -- just edited. These are Windows files. The Splunk Enterprise instance is installed on a Windows 2008 R2 server. These files are stored locally. &lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2015 14:06:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165194#M33504</guid>
      <dc:creator>ceichhorn</dc:creator>
      <dc:date>2015-04-24T14:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165195#M33505</link>
      <description>&lt;P&gt;HI,&lt;BR /&gt;
when you choose "continuously indexing a file", the path of that file and the name of the file must not change. If one of them change, splunk'll not be able to index that file.&lt;BR /&gt;
If you respect those conditions and your index file is heavy, be patien because i had files that take me more than 45 mn to be indexed&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2015 14:13:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165195#M33505</guid>
      <dc:creator>NOUMSSI</dc:creator>
      <dc:date>2015-04-24T14:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165196#M33506</link>
      <description>&lt;P&gt;hi,&lt;BR /&gt;
following this link: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.2/Data/WhatSplunkcanmonitor"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.2/Data/WhatSplunkcanmonitor&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;on page 45, look this specification&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Via Splunk Home:

1. Click the Add Data link in Splunk Home.
2. Click Upload to upload a file, Monitor to monitor a file, or Forward to forward a file.
Note: Forwarding a file requires additional setup. See "Set up forwarding and  receiving" in the Forwarding Data manual.

B. Select the input source

1. To add a file or directory input, click Files &amp;amp; Directories.
2. In the File or Directory field, specify the full path to the file or directory. To monitor a shared network drive, enter the following: &amp;lt;myhost&amp;gt;/&amp;lt;mypath&amp;gt; (or  \\&amp;lt;myhost&amp;gt;\&amp;lt;mypath&amp;gt; on Windows). Make sure Splunk Enterprise has read access to the mounted drive, as well as to the files you wish to monitor.
3. Choose how you want Splunk Enterprise to monitor the file:
 ·`Continuously Monitor`. Sets up an ongoing input. Splunk Enterprise
monitors the file continuously for new data. Read the next section for
advanced options specific to this choice.

· `Index Once`. Copies a file on the server into Splunk Enterprise.
4. Click the green Next button.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 24 Apr 2015 14:13:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165196#M33506</guid>
      <dc:creator>gyslainlatsa</dc:creator>
      <dc:date>2015-04-24T14:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165197#M33507</link>
      <description>&lt;P&gt;Hi Noumssi,&lt;/P&gt;

&lt;P&gt;Where is the "continuously indexing a file" option? I think that's my problem; I can't find that option in Splunk.  I am not changing the file name and I have waited 24 hours. &lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2015 14:17:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165197#M33507</guid>
      <dc:creator>ceichhorn</dc:creator>
      <dc:date>2015-04-24T14:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165198#M33508</link>
      <description>&lt;P&gt;which version of splunk do you use?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2015 14:22:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165198#M33508</guid>
      <dc:creator>NOUMSSI</dc:creator>
      <dc:date>2015-04-24T14:22:12Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165199#M33509</link>
      <description>&lt;P&gt;This is splunk 6.2. &lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2015 14:27:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165199#M33509</guid>
      <dc:creator>ceichhorn</dc:creator>
      <dc:date>2015-04-24T14:27:50Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165200#M33510</link>
      <description>&lt;P&gt;ok&lt;BR /&gt;
 1. click on  &lt;STRONG&gt;add data&lt;/STRONG&gt;&lt;BR /&gt;
 2. click on &lt;STRONG&gt;monitor&lt;/STRONG&gt;&lt;BR /&gt;
 3. &lt;STRONG&gt;files &amp;amp; directories&lt;/STRONG&gt;&lt;BR /&gt;
 4. give the path and then click on continuously monitor&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2015 14:40:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165200#M33510</guid>
      <dc:creator>NOUMSSI</dc:creator>
      <dc:date>2015-04-24T14:40:59Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165201#M33511</link>
      <description>&lt;P&gt;Thanks Noum, I see it now. I think, however, that option was already chosen. Now I have to figure out why it's not actually updating. &lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2015 14:51:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165201#M33511</guid>
      <dc:creator>ceichhorn</dc:creator>
      <dc:date>2015-04-24T14:51:11Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165202#M33512</link>
      <description>&lt;P&gt;make sure that this option is choosed and wait sometime, the updating'll be done&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2015 14:58:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165202#M33512</guid>
      <dc:creator>NOUMSSI</dc:creator>
      <dc:date>2015-04-24T14:58:46Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165203#M33513</link>
      <description>&lt;P&gt;CHECK IF THE SOURCE OR THE FILE HAVE NOT BEEN BLACKLISTED.&lt;/P&gt;

&lt;P&gt;docs.splunk.com/Documentation/Splunk/6.2.2/Data/Whitelistorblacklistspecificincomingdata&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2015 18:42:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-files-on-a-local-Windows-2008-R2-server-why-aren-t/m-p/165203#M33513</guid>
      <dc:creator>stephane_cyrill</dc:creator>
      <dc:date>2015-04-24T18:42:12Z</dc:date>
    </item>
  </channel>
</rss>

