<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ** Urgent ** - Question on how to specify DIRECTORY on unix system to index data from the files within directory in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Urgent-Question-on-how-to-specify-DIRECTORY-on-unix-system-to/m-p/82500#M181923</link>
    <description>&lt;P&gt;from the search view (&lt;CODE&gt;flashtimeline&lt;/CODE&gt;) you can search with &lt;CODE&gt;index=_internal&lt;/CODE&gt; and search for some of yours files as search arguments (probably using wildcards to make things easier)&lt;/P&gt;</description>
    <pubDate>Mon, 08 Oct 2012 07:51:52 GMT</pubDate>
    <dc:creator>MHibbin</dc:creator>
    <dc:date>2012-10-08T07:51:52Z</dc:date>
    <item>
      <title>** Urgent ** - Question on how to specify DIRECTORY on unix system to index data from the files within directory</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Urgent-Question-on-how-to-specify-DIRECTORY-on-unix-system-to/m-p/82495#M181918</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;

&lt;P&gt;I need a help in indexing whole DIRECTORY to index data from files residing in directory.&lt;BR /&gt;
My directory is " /proj_data " and there are some 250-300 files in this directory.&lt;/P&gt;

&lt;P&gt;Here's what i do:&lt;/P&gt;

&lt;P&gt;I add data from " a file or directory of files". I browse server to select directory. When i select directory and try to proceed further by clicking "select" button it remains disabled. But if i click a file withing /proj_data it gets enabled. &lt;/P&gt;

&lt;P&gt;So i am not able to select whole directory but a single file only. &lt;/P&gt;

&lt;P&gt;Any idea on how do i index chunk of files together ? or it is not possible with splunk ??&lt;/P&gt;</description>
      <pubDate>Sun, 07 Oct 2012 05:50:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Urgent-Question-on-how-to-specify-DIRECTORY-on-unix-system-to/m-p/82495#M181918</guid>
      <dc:creator>mehal</dc:creator>
      <dc:date>2012-10-07T05:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: ** Urgent ** - Question on how to specify DIRECTORY on unix system to index data from the files within directory</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Urgent-Question-on-how-to-specify-DIRECTORY-on-unix-system-to/m-p/82496#M181919</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;It is possible, I think if you are using the web UI then you are also probably trying to preview the file before indexing... this, for fairly obvious reasons, will not work as the files in the directory may be completely different to each other. There should be an option to skip preview, and you also want to manually type in the path to the file.&lt;/P&gt;

&lt;P&gt;You should read the following documentation (instead of re-inventing the wheel)...&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Data/Monitorfilesanddirectories"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Data/Monitorfilesanddirectories&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Data/UseSplunkWeb"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Data/UseSplunkWeb&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I would recommend setting up this monitor through the &lt;CODE&gt;inputs.conf&lt;/CODE&gt; file, as this should give you more flexibility...&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Data/Editinputs.conf"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Data/Editinputs.conf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps,&lt;/P&gt;

&lt;P&gt;MHibbin&lt;/P&gt;</description>
      <pubDate>Sun, 07 Oct 2012 08:47:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Urgent-Question-on-how-to-specify-DIRECTORY-on-unix-system-to/m-p/82496#M181919</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2012-10-07T08:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: ** Urgent ** - Question on how to specify DIRECTORY on unix system to index data from the files within directory</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Urgent-Question-on-how-to-specify-DIRECTORY-on-unix-system-to/m-p/82497#M181920</link>
      <description>&lt;P&gt;HI MHibbin,&lt;/P&gt;

&lt;P&gt;I tried above approach but no luck. when i try with splunk web by selecting skip preview -&amp;gt; continuously index data...splunk can access -&amp;gt; full path (/proj_data/)-&amp;gt; save.&lt;BR /&gt;
It does adds data input with equal number of files on data inputs. But i dont see any data getting indexed ? &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;I also tried same with changing inputs.conf at /local/inputs.conf but same thing happens and no data getting indexed.&lt;/P&gt;

&lt;P&gt;How can i verify that data is getting index.&lt;/P&gt;

&lt;P&gt;My files are .csv files in /proj_data folder.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Oct 2012 19:47:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Urgent-Question-on-how-to-specify-DIRECTORY-on-unix-system-to/m-p/82497#M181920</guid>
      <dc:creator>mehal</dc:creator>
      <dc:date>2012-10-07T19:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: ** Urgent ** - Question on how to specify DIRECTORY on unix system to index data from the files within directory</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Urgent-Question-on-how-to-specify-DIRECTORY-on-unix-system-to/m-p/82498#M181921</link>
      <description>&lt;P&gt;Also could state if i specify data from splunkweb then those details appear in /local/inputs.conf or /default/inputs.conf?. Because i dont see any details when i added data input from splunkweb in inputs.conf in either location.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Oct 2012 20:04:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Urgent-Question-on-how-to-specify-DIRECTORY-on-unix-system-to/m-p/82498#M181921</guid>
      <dc:creator>mehal</dc:creator>
      <dc:date>2012-10-07T20:04:42Z</dc:date>
    </item>
    <item>
      <title>Re: ** Urgent ** - Question on how to specify DIRECTORY on unix system to index data from the files within directory</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Urgent-Question-on-how-to-specify-DIRECTORY-on-unix-system-to/m-p/82499#M181922</link>
      <description>&lt;P&gt;Have you made certain that Splunk has permission to read the files? i.e. The files either have global level read permissions, or the user running splunk is in a group that has permissions to read the file?&lt;/P&gt;

&lt;P&gt;You should typically edit &lt;CODE&gt;inputs.conf&lt;/CODE&gt; files in the local directory (e.g. &lt;CODE&gt;$SPLUNK_HOME/etc/apps/search/local/inputs.conf&lt;/CODE&gt;), as the default folder is usually used for global defaults (i.e. if an app is posted on SB, it will have configs in default, allowing local users to customise local configs.)&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2012 07:50:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Urgent-Question-on-how-to-specify-DIRECTORY-on-unix-system-to/m-p/82499#M181922</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2012-10-08T07:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: ** Urgent ** - Question on how to specify DIRECTORY on unix system to index data from the files within directory</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Urgent-Question-on-how-to-specify-DIRECTORY-on-unix-system-to/m-p/82500#M181923</link>
      <description>&lt;P&gt;from the search view (&lt;CODE&gt;flashtimeline&lt;/CODE&gt;) you can search with &lt;CODE&gt;index=_internal&lt;/CODE&gt; and search for some of yours files as search arguments (probably using wildcards to make things easier)&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2012 07:51:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Urgent-Question-on-how-to-specify-DIRECTORY-on-unix-system-to/m-p/82500#M181923</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2012-10-08T07:51:52Z</dc:date>
    </item>
  </channel>
</rss>

