Getting Data In

Files are not indexing automatically when selected Monitor Files & Directories

vikrantkumar199
New Member

I have configured to monitor a directory which has JSON file under it. But after submitting everything when I searched, it does not show any result. When I looked into "Data inputs » Files & directories", Number of files it is showing 1 which is correct as only one file is available as of now in the directory. And, when I looked into particular index, it is showing "Event count" 0 which is not increasing. Even tried to refresh multiple times but no luck. Any guidance is highly appreciated. thanks in advance.

0 Karma

skalliger
SplunkTrust
SplunkTrust

If you search for index=* and put in your source=*your_file, what do you see? Do you see maybe a typo in the index name or even the index main? If the latter, the config is not working and using the default index.

Skalli

0 Karma
Get Updates on the Splunk Community!

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...

Security Newsletter Updates | March 2023

 March 2023 | Check out the latest and greatestUnify Your Security Operations with Splunk Mission Control The ...

Platform Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestIntroducing Splunk Edge Processor, simplified data ...