<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: index same file but where the file name is different in splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/index-same-file-but-where-the-file-name-is-different-in-splunk/m-p/514293#M87154</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/193316"&gt;@surekhasplunk&lt;/a&gt;&amp;nbsp;&amp;nbsp;You have log file&amp;nbsp;&lt;SPAN&gt;myfile_ddmmyyyy.log under&amp;nbsp;/asbc/logs/*.log on server and you have given below stanza right ? Please check if you gave below stanza in inputs.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[&lt;EM&gt;monitor&lt;/EM&gt;:///asbc/logs/*.log]&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;disabled = 0&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;sourcetype = _json&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;index = abc&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please check below once above stanza is added:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1) Are you using deployment server ? If yes, make sure you have added the server in serverclass.conf&lt;BR /&gt;2) Make sure the deployment server details are corret in deploymentclient.conf&lt;BR /&gt;3) Make sure the Splunk Forwarder is up and running. Try restart&lt;BR /&gt;4) Verify if the port 8089 is open&lt;BR /&gt;5) Verify you are able to connect to deployement server through 8089 using telnet from server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 16 Aug 2020 07:38:10 GMT</pubDate>
    <dc:creator>venkateshparank</dc:creator>
    <dc:date>2020-08-16T07:38:10Z</dc:date>
    <item>
      <title>index same file but where the file name is different in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/index-same-file-but-where-the-file-name-is-different-in-splunk/m-p/514278#M87153</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am currenlty monitoring ///asbc/logs/*.log&lt;/P&gt;&lt;P&gt;and this folder gets updated everyday with a file called myfile_ddmmyyyy.log&lt;/P&gt;&lt;P&gt;But since the many a days there is no change or update in the log file it doesn't get indexed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using crcSalt also but no luck. its not getting indexed. Please help&lt;/P&gt;&lt;P&gt;disabled = false&lt;BR /&gt;index = abc&lt;BR /&gt;sourcetype = _json&lt;BR /&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Aug 2020 03:08:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/index-same-file-but-where-the-file-name-is-different-in-splunk/m-p/514278#M87153</guid>
      <dc:creator>surekhasplunk</dc:creator>
      <dc:date>2020-08-16T03:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: index same file but where the file name is different in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/index-same-file-but-where-the-file-name-is-different-in-splunk/m-p/514293#M87154</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/193316"&gt;@surekhasplunk&lt;/a&gt;&amp;nbsp;&amp;nbsp;You have log file&amp;nbsp;&lt;SPAN&gt;myfile_ddmmyyyy.log under&amp;nbsp;/asbc/logs/*.log on server and you have given below stanza right ? Please check if you gave below stanza in inputs.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[&lt;EM&gt;monitor&lt;/EM&gt;:///asbc/logs/*.log]&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;disabled = 0&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;sourcetype = _json&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;index = abc&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please check below once above stanza is added:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1) Are you using deployment server ? If yes, make sure you have added the server in serverclass.conf&lt;BR /&gt;2) Make sure the deployment server details are corret in deploymentclient.conf&lt;BR /&gt;3) Make sure the Splunk Forwarder is up and running. Try restart&lt;BR /&gt;4) Verify if the port 8089 is open&lt;BR /&gt;5) Verify you are able to connect to deployement server through 8089 using telnet from server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Aug 2020 07:38:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/index-same-file-but-where-the-file-name-is-different-in-splunk/m-p/514293#M87154</guid>
      <dc:creator>venkateshparank</dc:creator>
      <dc:date>2020-08-16T07:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: index same file but where the file name is different in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/index-same-file-but-where-the-file-name-is-different-in-splunk/m-p/514305#M87157</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;if the file not exists or it’s content is empty there is nothing to index to splunk. Splunk can only index those events not just filenames.&lt;/P&gt;&lt;P&gt;Or was the situation that there are those files with different content and they still didn’t indexed to splunk?&lt;/P&gt;&lt;P&gt;An additional comment as you are using sourcetype _json, the best practices is define your own sourcetype for json based event not use this “example” sourcetype.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Sun, 16 Aug 2020 11:17:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/index-same-file-but-where-the-file-name-is-different-in-splunk/m-p/514305#M87157</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-16T11:17:10Z</dc:date>
    </item>
  </channel>
</rss>

