Getting Data In

Folder monitoring and whitelist

kennethyeung
New Member

i used web to setup the folder monitor
settng -> Data inputs » Files & directories »
but in the whitelist if i *.csv , it wont index even the file extension is csv.

i saw the doc is to edit inputs.conf

but in the system/local/inputs.conf i cannot find the folder path i setup in web.
so dont know where it is

Thanks

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The inputs.conf file will be saved under the app you were using when you selected Settings->Data Inputs. It's not likely to be in system/local. Try search/local and if it's not there, use your Linux-fu to find the inputs.conf file that changed most recently.

Once you find the file, post the relevant stanza here and we can help you fix it.

---
If this reply helps you, Karma would be appreciated.
0 Karma

kennethyeung
New Member

Thanks, i found the correct inputs.conf
if i want to only index csv and *.idx
.csv$|.idx$

am i correct, i will keep monitor a while
Thank again

0 Karma

desmondw_splunk
Splunk Employee
Splunk Employee

Hi,
I think the syntax should be like :-
whitelist = \.csv$|\.idx$

Cheers !

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...