Getting Data In

Folder monitoring and whitelist

kennethyeung
New Member

i used web to setup the folder monitor
settng -> Data inputs » Files & directories »
but in the whitelist if i *.csv , it wont index even the file extension is csv.

i saw the doc is to edit inputs.conf

but in the system/local/inputs.conf i cannot find the folder path i setup in web.
so dont know where it is

Thanks

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The inputs.conf file will be saved under the app you were using when you selected Settings->Data Inputs. It's not likely to be in system/local. Try search/local and if it's not there, use your Linux-fu to find the inputs.conf file that changed most recently.

Once you find the file, post the relevant stanza here and we can help you fix it.

---
If this reply helps you, an upvote would be appreciated.
0 Karma

kennethyeung
New Member

Thanks, i found the correct inputs.conf
if i want to only index csv and *.idx
.csv$|.idx$

am i correct, i will keep monitor a while
Thank again

0 Karma

desmondw_splunk
Splunk Employee
Splunk Employee

Hi,
I think the syntax should be like :-
whitelist = \.csv$|\.idx$

Cheers !

0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>