Monitoring Splunk

How to check status of indexing?

pradjswl
Explorer

I am using splunk-enterprise in my local machine. I have configured 4 Files/Directory monitoring for the data indexing. I added one file in all of the directory. I dont see the data from 4ht directory getting indexed and shown in splunk result. Thought i do see the data from other 3 directory getting indexed and displayed in search result. Is there a way I can check the status if the data from that directory is really indexed or not . I am looking for an approach other than searching for that data in search query, as I already know the search is not returning the result from that source type.

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Since you have 3 of the 4 directories indexed we can monitoring is working correctly. That means either 1) the monitor settings for the 4th directory are incorrect; or 2) the query searching for directory 4 is incorrect. Double-check your monitor settings and compare them to your query.

---
If this reply helps you, Karma would be appreciated.
0 Karma

DalJeanis
SplunkTrust
SplunkTrust

I'd also carefully check the conf settings for the fourth source type and see if any values have not been updated correctly.

I'd also do a quick search to see if maybe the results WAS indexed, but was marked with the wrong sourcetype...

(a search that returns one specific record from the test file) 
| stats count as totalcount dc(sourcetype) as distinctcount by _raw
0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...