Getting Data In

Files are not indexing automatically when selected Monitor Files & Directories

New Member

I have configured to monitor a directory which has JSON file under it. But after submitting everything when I searched, it does not show any result. When I looked into "Data inputs » Files & directories", Number of files it is showing 1 which is correct as only one file is available as of now in the directory. And, when I looked into particular index, it is showing "Event count" 0 which is not increasing. Even tried to refresh multiple times but no luck. Any guidance is highly appreciated. thanks in advance.

0 Karma


If you search for index=* and put in your source=*your_file, what do you see? Do you see maybe a typo in the index name or even the index main? If the latter, the config is not working and using the default index.


0 Karma
Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...