<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitoring a text file Issue in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-a-text-file-Issue/m-p/439355#M6258</link>
    <description>&lt;P&gt;[monitor://C:\CWXTI\ServerInfo_Tag.txt]&lt;BR /&gt;
crcSalt = &lt;BR /&gt;
sourcetype = SENT&lt;BR /&gt;
index = wineventlog&lt;/P&gt;</description>
    <pubDate>Wed, 13 Mar 2019 13:45:44 GMT</pubDate>
    <dc:creator>Channu</dc:creator>
    <dc:date>2019-03-13T13:45:44Z</dc:date>
    <item>
      <title>Monitoring a text file Issue</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-a-text-file-Issue/m-p/439354#M6257</link>
      <description>&lt;P&gt;I am trying to extract some information from a text file. This is how my inputs.conf looks like,&lt;/P&gt;

&lt;P&gt;[monitor://C:\Temp\ServerInfo_Tag.txt]&lt;BR /&gt;
sourcetype = ABC&lt;BR /&gt;
index = filelog&lt;BR /&gt;
crcSalt = &lt;/P&gt;

&lt;P&gt;I pushed this config across 4000 windows servers. Ideally Splunk should pickup the file content as soon as the config is pushed.&lt;/P&gt;

&lt;P&gt;But strange thing here is, I can see the file content as an event on Splunk for ONLY 3000 servers. &lt;BR /&gt;
For the other 1000 servers I have to modify the file to get the file content on Splunk.&lt;/P&gt;

&lt;P&gt;Is there a way to get the file content without modifying the file? &lt;/P&gt;

&lt;P&gt;Config doesn't seem to be an issue here as it it working for other servers and there are no port related issues on the other 1000 servers as I can see the data on Splunk after modifying the file.&lt;/P&gt;

&lt;P&gt;Any suggestions here are highly appreciated.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Channesh &lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 13:31:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-a-text-file-Issue/m-p/439354#M6257</guid>
      <dc:creator>Channu</dc:creator>
      <dc:date>2019-03-13T13:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a text file Issue</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-a-text-file-Issue/m-p/439355#M6258</link>
      <description>&lt;P&gt;[monitor://C:\CWXTI\ServerInfo_Tag.txt]&lt;BR /&gt;
crcSalt = &lt;BR /&gt;
sourcetype = SENT&lt;BR /&gt;
index = wineventlog&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 13:45:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-a-text-file-Issue/m-p/439355#M6258</guid>
      <dc:creator>Channu</dc:creator>
      <dc:date>2019-03-13T13:45:44Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a text file Issue</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-a-text-file-Issue/m-p/439356#M6259</link>
      <description>&lt;P&gt;I would check splunkd.log (index=_internal sourcetype=splunkd host=yourWinServer) for errors for the file. Are you restarting splunk on your windows servers after pushing the configurations (handled by restartSplunkd attribute on serverclass.conf)?  &lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 14:36:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-a-text-file-Issue/m-p/439356#M6259</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-03-13T14:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a text file Issue</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-a-text-file-Issue/m-p/439357#M6260</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/15147"&gt;@somesoni2&lt;/a&gt;  I could these logs related to the file I am monitoring.&lt;BR /&gt;
03-12-2019 11:21:56.938 -0400 INFO  TailingProcessor - Parsing configuration stanza: monitor://C:\CWXTI\ServerInfo_Tag.txt.&lt;BR /&gt;
03-12-2019 11:21:56.938 -0400 INFO  TailingProcessor - Parsing configuration stanza: monitor://C:\Program Files\CernerESM\sentinel\sentinel.config.&lt;BR /&gt;
03-12-2019 11:21:56.938 -0400 INFO  TailReader - State transitioning from 1 to 0 (initOrResume).&lt;BR /&gt;
03-12-2019 11:21:56.938 -0400 INFO  TailReader - State transitioning from 1 to 0 (initOrResume).&lt;BR /&gt;
03-12-2019 11:21:56.938 -0400 INFO  TailingProcessor - Adding watch on path: C:\CWXTI\ServerInfo_Tag.txt.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:42:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-a-text-file-Issue/m-p/439357#M6260</guid>
      <dc:creator>Channu</dc:creator>
      <dc:date>2020-09-29T23:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a text file Issue</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-a-text-file-Issue/m-p/439358#M6261</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/15147"&gt;@somesoni2&lt;/a&gt;  Log has this information which is hard to understand.&lt;BR /&gt;
03-12-2019 11:21:56.938 -0400 INFO  TailingProcessor - Parsing configuration stanza: monitor://C:\CWXTI\ServerInfo_Tag.txt.&lt;BR /&gt;
03-12-2019 11:21:56.938 -0400 INFO  TailReader - State transitioning from 1 to 0 (initOrResume).&lt;BR /&gt;
03-12-2019 11:21:56.938 -0400 INFO  TailReader - State transitioning from 1 to 0 (initOrResume).&lt;BR /&gt;
03-12-2019 11:21:56.938 -0400 INFO  TailingProcessor - Adding watch on path: C:\CWXTI\ServerInfo_Tag.txt.&lt;/P&gt;

&lt;P&gt;Yes, servers are being restarted after pushing the configurations.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:42:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitoring-a-text-file-Issue/m-p/439358#M6261</guid>
      <dc:creator>Channu</dc:creator>
      <dc:date>2020-09-29T23:42:12Z</dc:date>
    </item>
  </channel>
</rss>

