All Apps and Add-ons

File monitoring not working

tomapatan
Communicator
My inputs.conf on the rasberryPi look like this:

 

[monitor:///var/log/pihole.log]
disabled = 0
sourcetype = pihole
index = main

[monitor:///var/log/pihole-FTL.log]
disabled = 0
sourcetype = pihole:ftl
index = main

 

 
Both log files exist in /var/log, but only one sourcetype gets sent to my indexer and that`s "pihole:ftl".
Any assistance would be greatly appreciated.
Labels (1)
0 Karma
1 Solution

tomapatan
Communicator

Hi @gcusello ,

Thanks for getting back to me. Turns out the splunk user did not have access to the pihole.log, only to the pihole-FTL.log files.

Splunk started to ingest both files after I changed the permissions.

Thanks,

Toma.

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @tomapatan,

check if the two files have the same content, even if a different name: Splunk doesn't index twice the same log.

If this is the issue, you can use crcSalt = <SOURCE> option in inputs.conf to index both files.

[monitor:///var/log/pihole.log]
disabled = 0
sourcetype = pihole
index = your_index
crcSalt = <SOURCE>
 
[monitor:///var/log/pihole-FTL.log]
disabled = 0
sourcetype = pihole:ftl
index = your_index
crcSalt = <SOURCE>

One additional my personal hint: don't use main index, create a custom one: not many indexes, few ones but not main.

Ciao.

Giuseppe

tomapatan
Communicator

Hi @gcusello ,

Thanks for getting back to me. Turns out the splunk user did not have access to the pihole.log, only to the pihole-FTL.log files.

Splunk started to ingest both files after I changed the permissions.

Thanks,

Toma.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...