All Apps and Add-ons

File monitoring not working

tomapatan
Communicator
My inputs.conf on the rasberryPi look like this:

 

[monitor:///var/log/pihole.log]
disabled = 0
sourcetype = pihole
index = main

[monitor:///var/log/pihole-FTL.log]
disabled = 0
sourcetype = pihole:ftl
index = main

 

 
Both log files exist in /var/log, but only one sourcetype gets sent to my indexer and that`s "pihole:ftl".
Any assistance would be greatly appreciated.
Labels (1)
0 Karma
1 Solution

tomapatan
Communicator

Hi @gcusello ,

Thanks for getting back to me. Turns out the splunk user did not have access to the pihole.log, only to the pihole-FTL.log files.

Splunk started to ingest both files after I changed the permissions.

Thanks,

Toma.

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @tomapatan,

check if the two files have the same content, even if a different name: Splunk doesn't index twice the same log.

If this is the issue, you can use crcSalt = <SOURCE> option in inputs.conf to index both files.

[monitor:///var/log/pihole.log]
disabled = 0
sourcetype = pihole
index = your_index
crcSalt = <SOURCE>
 
[monitor:///var/log/pihole-FTL.log]
disabled = 0
sourcetype = pihole:ftl
index = your_index
crcSalt = <SOURCE>

One additional my personal hint: don't use main index, create a custom one: not many indexes, few ones but not main.

Ciao.

Giuseppe

tomapatan
Communicator

Hi @gcusello ,

Thanks for getting back to me. Turns out the splunk user did not have access to the pihole.log, only to the pihole-FTL.log files.

Splunk started to ingest both files after I changed the permissions.

Thanks,

Toma.

Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...