Deployment Architecture

Data Ingestion Only Works After Restart of Splunk

ericpacker
Engager

Scenario:
I am using a script to poll cloud API for data at frequent intervals. The data is stored in archived *.csv.gz files and a UF installed on the same server is configured to monitor the folder:

inputs.conf
[monitor:///apps/splunk/data]
sourcetype = data:1
index = data_1
_TCP_ROUTING = primary_indexers_site_1

The problem is that data only get ingested after a restart of the UF Splunk service on the host, and then almost immediately stops. Meaning I have to restart the UF every time I want to get new/current data.

The script does not appear to be the issue because it is constantly pulling new data into the folder as expected.

Anyone seen this before?

Get Updates on the Splunk Community!

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...

Splunkbase | Splunk Dashboard Examples App for SimpleXML End of Life

The Splunk Dashboard Examples App for SimpleXML will reach end of support on Dec 19, 2024, after which no new ...

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...