Getting Data In

File and Dir File Monitoring not working?

DesertSocBum
Explorer

Setup an app folder on my search head (clustered with indexers and HECS)  "TA-Whatever"  from the app builder. Dropped a  py script in the default folder inside TA-whatever that gens a json file that gets dropped in the parent app TA-whatever folder. 

When going to the add data, file and directory menu, I wen thru the server file system drop downs and selected the  json file and on the 2nd page where you select the sourcetype it sees the  json data.  After I select my index, source type and all that, finish, restart Splunk, and search the index,  I see nothing, no data is there.

 

I have rebuilt the app several times as the Splunk user,  as root.  chmod everything to 777. rebuild source types and index's. did props conf, treid with no entry in props.  added inputs conf to the local app folder, tried with no input.conf in the ta-whatever local folder,  also added a monitor to the global inputs.conf in etc/sys/local and still no dice.

 

here is my input.conf that i tried in global and the local app directory:

[monitor://tmp/felt.json]
disabled = 0
index = googlepyscript
sourcetype = googlepy

 

also tried:

 

[monitor:///tmp/felt.json]
disabled = 0
index = googlepyscript
sourcetype = googlepy

 

 

No matter what I do the index is not getting data. I have tried it with the build in _json sourcetype and created my own and no data goes to the index after I finish the wizard.   Any input is welcomed at this point as I have been going at it for several days. Thanks! 

Labels (2)
0 Karma
1 Solution

DesertSocBum
Explorer

I have solved this sort of.. for some reason the new index I created wont take data. Once I re-did all this and pointed it to an older index it started to work. 

View solution in original post

0 Karma

DesertSocBum
Explorer

I have solved this sort of.. for some reason the new index I created wont take data. Once I re-did all this and pointed it to an older index it started to work. 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...