Getting Data In

Good Data Input .. No Indexing

vbrtrmn
Explorer

I have a data source on the local file system configured as such..

Path:

/data/splunk/rrsearch/server-01/processed.1341878400.gz
/data/splunk/rrsearch/server-01/processed.1341964800.gz
/data/splunk/rrsearch/server-02/processed.1341878400.gz
/data/splunk/rrsearch/server-02/processed.1341964800.gz
/data/splunk/rrsearch/server-03/processed.1341878400.gz
/data/splunk/rrsearch/server-03/processed.1341964800.gz
...etc...
  • Path: /data/logs/rrsearch
  • Set Host: Segment on Path / 4
  • Source type: Manual / Baseline Search
  • Index: baseline_search
  • Whitelist: .+processed.+gz$
  • Blacklist: left empty

The Data Inputs - Files & Directories screen shows 620 files.

The problem is none of the data ever seems to get indexed, other data in the /data/splunk path does get indexed for other projects. I feel I'm missing one small step, can anyone throw me a bone?

Per @Lamar's request, inputs.conf

[default]
host = wsi-hub

[monitor:///data/splunk/remote]
host_segment = 4
sourcetype = syslog
blacklist = .*.gz
disabled = 0
host = 

[monitor://$SPLUNK_HOME/var/log/splunk]
blacklist = *.gz
disabled = false

[monitor:///data/logs/rrsearch]
disabled = false
followTail = 0
host = 
host_regex = 
index = baseline_search
whitelist = .+processed.+gz$
sourcetype = Baseline Search
host_segment = 4

In indexes:

Index Name: baseline_search
Max Size: 500,000
Frozen Archive: None 
Current Size: 3,807
Event Count: 54,237,503
Earliest Event: May 13, 2012 7:59:59 PM
Latest Event: Jul 30, 2012 7:59:59 PM
Home Path: /opt/splunk/var/lib/splunk/baseline_search/db
App: search
Tags (2)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...