<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitor a directory for new files in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-directory-for-new-files/m-p/189874#M37817</link>
    <description>&lt;P&gt;I have made changes in C:\Program Files\Splunk\etc\apps\search\local\inputs.conf.&lt;BR /&gt;
i have aslo gone through web ui. I found there status= enabled and no. of file = 1.&lt;/P&gt;</description>
    <pubDate>Mon, 18 May 2015 12:58:19 GMT</pubDate>
    <dc:creator>adityaanand</dc:creator>
    <dc:date>2015-05-18T12:58:19Z</dc:date>
    <item>
      <title>Monitor a directory for new files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-directory-for-new-files/m-p/189866#M37809</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I am trying to monitor a directory.&lt;BR /&gt;
Suppose that there is a directory named &lt;STRONG&gt;test&lt;/STRONG&gt; and it contains initially a log file called access.log.&lt;BR /&gt;
The &lt;STRONG&gt;access.log&lt;/STRONG&gt; file  contains following data.&lt;BR /&gt;
210.160.24.63 - - [07/May/2015:18:22:16] "GET /product.screen?productId=WC-SH-A02&amp;amp;JSESSIONID=SD0SL6FF7ADFF4953 HTTP 1.1" 200 3878 "&lt;A href="http://www.google.com"&gt;http://www.google.com&lt;/A&gt;" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.46 Safari/536.5" 349&lt;BR /&gt;
.....&lt;BR /&gt;
.....&lt;BR /&gt;
It is showing that &lt;STRONG&gt;13,628&lt;/STRONG&gt; events are indexed.&lt;/P&gt;

&lt;P&gt;Now i added an another file &lt;STRONG&gt;access1.log&lt;/STRONG&gt; in same directory (test). with little with changes in the file. I have replace &lt;STRONG&gt;210.160.24.63&lt;/STRONG&gt; with &lt;STRONG&gt;190.160.24.63&lt;/STRONG&gt; and all other contents are same as it is.&lt;/P&gt;

&lt;P&gt;But still in search It is showing that &lt;STRONG&gt;13,628&lt;/STRONG&gt; events .&lt;/P&gt;

&lt;P&gt;I have checked that through CLI that both files are listed in monitor directory.&lt;/P&gt;

&lt;P&gt;But i am not getting expected results i.e. events should be increased. &lt;/P&gt;

&lt;P&gt;Please help me .&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2015 12:11:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-directory-for-new-files/m-p/189866#M37809</guid>
      <dc:creator>adityaanand</dc:creator>
      <dc:date>2015-05-18T12:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor a directory for new files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-directory-for-new-files/m-p/189867#M37810</link>
      <description>&lt;P&gt;Are the first few lines of the documents exactly the same? Or did the change of the ip influence the also the first few lines of the document?&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2015 12:18:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-directory-for-new-files/m-p/189867#M37810</guid>
      <dc:creator>tom_frotscher</dc:creator>
      <dc:date>2015-05-18T12:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor a directory for new files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-directory-for-new-files/m-p/189868#M37811</link>
      <description>&lt;P&gt;No the first line of the document is not exactly same.&lt;BR /&gt;
I have already mentioned that the first line stated with 210.160.24.63 ... is replaced with 190.160.24.63 and rest of are exactly same.&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2015 12:22:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-directory-for-new-files/m-p/189868#M37811</guid>
      <dc:creator>adityaanand</dc:creator>
      <dc:date>2015-05-18T12:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor a directory for new files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-directory-for-new-files/m-p/189869#M37812</link>
      <description>&lt;P&gt;Ok, sorry but from your post it was not completely clear for me that you changed the first line.&lt;/P&gt;

&lt;P&gt;Can you provide the corresponding monitoring stanza from your inputs.conf ?&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2015 12:27:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-directory-for-new-files/m-p/189869#M37812</guid>
      <dc:creator>tom_frotscher</dc:creator>
      <dc:date>2015-05-18T12:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor a directory for new files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-directory-for-new-files/m-p/189870#M37813</link>
      <description>&lt;P&gt;[monitor://D:/\Splunk Data/\Testing]&lt;BR /&gt;
disabled = true&lt;BR /&gt;
index = splunk_test&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2015 12:35:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-directory-for-new-files/m-p/189870#M37813</guid>
      <dc:creator>adityaanand</dc:creator>
      <dc:date>2015-05-18T12:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor a directory for new files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-directory-for-new-files/m-p/189871#M37814</link>
      <description>&lt;P&gt;Your input is disabled, change to disabled = false.&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2015 12:36:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-directory-for-new-files/m-p/189871#M37814</guid>
      <dc:creator>tom_frotscher</dc:creator>
      <dc:date>2015-05-18T12:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor a directory for new files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-directory-for-new-files/m-p/189872#M37815</link>
      <description>&lt;P&gt;I have changed to disabled = false.&lt;BR /&gt;
Still i am getting same result.&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2015 12:42:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-directory-for-new-files/m-p/189872#M37815</guid>
      <dc:creator>adityaanand</dc:creator>
      <dc:date>2015-05-18T12:42:26Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor a directory for new files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-directory-for-new-files/m-p/189873#M37816</link>
      <description>&lt;P&gt;Have you changed this setting in the default or in the local directory? Can you find your input in the  web ui? In the web ui and in the correct app context go to settings -&amp;gt; data inputs -&amp;gt; files and directories. Is your input in this list and displayed as "enabled"?&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2015 12:50:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-directory-for-new-files/m-p/189873#M37816</guid>
      <dc:creator>tom_frotscher</dc:creator>
      <dc:date>2015-05-18T12:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor a directory for new files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-directory-for-new-files/m-p/189874#M37817</link>
      <description>&lt;P&gt;I have made changes in C:\Program Files\Splunk\etc\apps\search\local\inputs.conf.&lt;BR /&gt;
i have aslo gone through web ui. I found there status= enabled and no. of file = 1.&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2015 12:58:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-directory-for-new-files/m-p/189874#M37817</guid>
      <dc:creator>adityaanand</dc:creator>
      <dc:date>2015-05-18T12:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor a directory for new files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-directory-for-new-files/m-p/189875#M37818</link>
      <description>&lt;P&gt;add crcSalt =  under your monitor stanza&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2015 13:41:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-a-directory-for-new-files/m-p/189875#M37818</guid>
      <dc:creator>kheli</dc:creator>
      <dc:date>2015-05-18T13:41:33Z</dc:date>
    </item>
  </channel>
</rss>

