<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk file monitoring issue in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-file-monitoring-issue/m-p/679765#M10050</link>
    <description>&lt;LI-CODE lang="markup"&gt;walmart_2.xml

walmart_3.xml

walmart_4.xml&lt;/LI-CODE&gt;
&lt;P&gt;Scenerio I&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When using below configuration in Inputs.conf we can able to monitor in splunk&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[monitor://D:\scada_server\walmart_2.xml]

disabled = false

host = WALVAU-VIDI-1

index = 2313917_2797418_scada

sourcetype = Scada_walmart_alarm

crcSalt = &amp;lt;SOURCE&amp;gt;

CHECK_METHOD = entire_md5&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Scenerio 2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hello Splunkers!!&lt;/P&gt;
&lt;P&gt;I need your help to fix this issue.&lt;BR /&gt;When using below configuration in Inputs.conf we can't able to monitor in splunk.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[monitor://D:\scada_server\walmart_*.xml]

disabled = false

host = WALVAU-VIDI-1

index = 2313917_2797418_scada

sourcetype = Scada_walmart_alarm

crcSalt = &amp;lt;SOURCE&amp;gt;

CHECK_METHOD = entire_md5&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please suggest some workaround.&lt;/P&gt;</description>
    <pubDate>Wed, 06 Mar 2024 11:21:55 GMT</pubDate>
    <dc:creator>uagraw01</dc:creator>
    <dc:date>2024-03-06T11:21:55Z</dc:date>
    <item>
      <title>Splunk file monitoring issue</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-file-monitoring-issue/m-p/679765#M10050</link>
      <description>&lt;LI-CODE lang="markup"&gt;walmart_2.xml

walmart_3.xml

walmart_4.xml&lt;/LI-CODE&gt;
&lt;P&gt;Scenerio I&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When using below configuration in Inputs.conf we can able to monitor in splunk&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[monitor://D:\scada_server\walmart_2.xml]

disabled = false

host = WALVAU-VIDI-1

index = 2313917_2797418_scada

sourcetype = Scada_walmart_alarm

crcSalt = &amp;lt;SOURCE&amp;gt;

CHECK_METHOD = entire_md5&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Scenerio 2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hello Splunkers!!&lt;/P&gt;
&lt;P&gt;I need your help to fix this issue.&lt;BR /&gt;When using below configuration in Inputs.conf we can't able to monitor in splunk.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[monitor://D:\scada_server\walmart_*.xml]

disabled = false

host = WALVAU-VIDI-1

index = 2313917_2797418_scada

sourcetype = Scada_walmart_alarm

crcSalt = &amp;lt;SOURCE&amp;gt;

CHECK_METHOD = entire_md5&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please suggest some workaround.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 11:21:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-file-monitoring-issue/m-p/679765#M10050</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-03-06T11:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk file monitoring issue</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-file-monitoring-issue/m-p/679770#M10051</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;sorry but I don't understand your question, anyway, then, why do are using crcSalt=&amp;lt;SOURCE&amp;gt;?&lt;/P&gt;&lt;P&gt;please try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor://D:\scada_server\walmart_*.xml]
disabled = false
host = WALVAU-VIDI-1
index = 2313917_2797418_scada
sourcetype = Scada_walmart_alarm
CHECK_METHOD = entire_md5&lt;/LI-CODE&gt;&lt;P&gt;Then why are you using a so complex index?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 11:12:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-file-monitoring-issue/m-p/679770#M10051</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-03-06T11:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk file monitoring issue</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-file-monitoring-issue/m-p/679772#M10052</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;&amp;nbsp;Hello,&amp;nbsp;&lt;SPAN&gt;&lt;SPAN class=""&gt;All&amp;nbsp;files&amp;nbsp;with&amp;nbsp;the.xml&amp;nbsp;extension,&amp;nbsp;such&amp;nbsp;as&amp;nbsp;/scada_server/walmart_1.xml,&amp;nbsp;/scada_server/walmart_2.xml,&amp;nbsp;/scada_server/walmart_3.xml,&amp;nbsp;and&amp;nbsp;so&amp;nbsp;forth,&amp;nbsp;are&amp;nbsp;matched&amp;nbsp;by&amp;nbsp;/walmart_*.xml. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Could&amp;nbsp;you&amp;nbsp;please&amp;nbsp;verify&amp;nbsp;the&amp;nbsp;permissions&amp;nbsp;for&amp;nbsp;every&amp;nbsp;file&amp;nbsp;inside&amp;nbsp;this&amp;nbsp;directory?And also,&amp;nbsp; You can try to remove the CrCSalt and try.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Check the below document for more examples:&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Specifyinputpathswithwildcards" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Specifyinputpathswithwildcards&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 11:20:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-file-monitoring-issue/m-p/679772#M10052</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2024-03-06T11:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk file monitoring issue</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-file-monitoring-issue/m-p/679786#M10053</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264857"&gt;@kiran_panchavat&lt;/a&gt;&amp;nbsp;I have permission on the directory as well. I tried without using crcSalt as well. But no luck was found.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 12:31:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-file-monitoring-issue/m-p/679786#M10053</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-03-06T12:31:46Z</dc:date>
    </item>
  </channel>
</rss>

