<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Newly created logs from a currently monitored directory is not showing in Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Newly-created-logs-from-a-currently-monitored-directory-is-not/m-p/199723#M39513</link>
    <description>&lt;P&gt;Anyway I used the same savedsearch i,e source=/var/log/myscriptlog.log and filtered it to All Time..&lt;/P&gt;</description>
    <pubDate>Wed, 18 Jun 2014 08:09:58 GMT</pubDate>
    <dc:creator>Isaias_Garcia</dc:creator>
    <dc:date>2014-06-18T08:09:58Z</dc:date>
    <item>
      <title>Newly created logs from a currently monitored directory is not showing in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Newly-created-logs-from-a-currently-monitored-directory-is-not/m-p/199720#M39510</link>
      <description>&lt;P&gt;I have the below config setup in inputs.conf to monitor all logs found in /var/log directory ( e.g. messages,mailog,named.log,secure log etc) and I can search them all in Splunk.&lt;/P&gt;

&lt;P&gt;[monitor:///var/log]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
followTail = 0&lt;BR /&gt;
host = pxxxxxxxxxxxdev&lt;BR /&gt;
index = dev&lt;/P&gt;

&lt;P&gt;However when I created a script  and passed its logs (myscriptlog.log) into /var/log/,the Splunk cannot search that log although I still use the same search query  "source=/var/log/*" and I also try "source=/var/log/myscriptlog.log" but there is 0 event though there is actually myscriptlog.log created in /var/log. Question: Do I need to restart inputs.conf although I did not change anything into it? Is there a Splunk command to search newly created log from the directory that is already being monitored and configured in inputs.conf?Please advise. Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2014 01:39:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Newly-created-logs-from-a-currently-monitored-directory-is-not/m-p/199720#M39510</guid>
      <dc:creator>Isaias_Garcia</dc:creator>
      <dc:date>2014-06-18T01:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: Newly created logs from a currently monitored directory is not showing in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Newly-created-logs-from-a-currently-monitored-directory-is-not/m-p/199721#M39511</link>
      <description>&lt;P&gt;Hi Isaias.Garcia,&lt;/P&gt;

&lt;P&gt;most commonly this is a permission problem and the account that runs splunk (on *nix Systems mostly &lt;CODE&gt;splunk&lt;/CODE&gt;) has no read rights in &lt;CODE&gt;/var/log&lt;/CODE&gt;. Also what can happen, is that your test log is too small.&lt;/P&gt;

&lt;P&gt;You can run this search as Splunk admin user:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal source="*splunkd.log*" TailingProcessor myscriptlog.log
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and see if the is anything related to your log file.&lt;/P&gt;

&lt;P&gt;hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2014 06:49:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Newly-created-logs-from-a-currently-monitored-directory-is-not/m-p/199721#M39511</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-06-18T06:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: Newly created logs from a currently monitored directory is not showing in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Newly-created-logs-from-a-currently-monitored-directory-is-not/m-p/199722#M39512</link>
      <description>&lt;P&gt;Thanks MuS. At first, it did not work but when I filter the time range to "All Time" the log's finally shown up so its quite weird because the logfile was just created last 24 hrs . Perhaps I will just filter my savedsearch to "All Time" for the time being. Thanks MuS&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2014 08:08:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Newly-created-logs-from-a-currently-monitored-directory-is-not/m-p/199722#M39512</guid>
      <dc:creator>Isaias_Garcia</dc:creator>
      <dc:date>2014-06-18T08:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: Newly created logs from a currently monitored directory is not showing in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Newly-created-logs-from-a-currently-monitored-directory-is-not/m-p/199723#M39513</link>
      <description>&lt;P&gt;Anyway I used the same savedsearch i,e source=/var/log/myscriptlog.log and filtered it to All Time..&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2014 08:09:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Newly-created-logs-from-a-currently-monitored-directory-is-not/m-p/199723#M39513</guid>
      <dc:creator>Isaias_Garcia</dc:creator>
      <dc:date>2014-06-18T08:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Newly created logs from a currently monitored directory is not showing in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Newly-created-logs-from-a-currently-monitored-directory-is-not/m-p/199724#M39514</link>
      <description>&lt;P&gt;you're welcome please mark this as answered  - thx&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2014 08:13:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Newly-created-logs-from-a-currently-monitored-directory-is-not/m-p/199724#M39514</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-06-18T08:13:22Z</dc:date>
    </item>
  </channel>
</rss>

