Dashboards & Visualizations

Data input from a directory not working sometimes

yiguanghu
Explorer

I have a directory on the splunk server. There are xml files in the directory. I have setup a sourcetype for the xml files and setup the splunk to load data from the directory continuously.
But somehow, it just don't work. I can load individual files from the directory with the same sourcetype without any problem.

I have another directory with different xml files and sourcetype and setup load data continuously and it works fine.

Any idea?

Thanks

0 Karma

pyi
Engager

I'm copying this from another place, it might apply here. I should get a commission from splunk
"
Check your splunkd.log for any logs related to this. Perhaps the files are too similar and you are getting a crccheck issue (where the crc of the files is too similar and splunk doesnt index because it thinks its the same file. Basically the first 250 chars of the files are the same, in this case look for crcSalt in inputs.conf)

Please read input.conf.spec for more information on [batch://] and crcSalt.
"

http://answers.splunk.com/answers/10727/data-input-monitor-a-directory-for-new-files-and-delete-when...

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...