I have a data source on the local file system configured as such..
Path:
/data/splunk/rrsearch/server-01/processed.1341878400.gz
/data/splunk/rrsearch/server-01/processed.1341964800.gz
/data/splunk/rrsearch/server-02/processed.1341878400.gz
/data/splunk/rrsearch/server-02/processed.1341964800.gz
/data/splunk/rrsearch/server-03/processed.1341878400.gz
/data/splunk/rrsearch/server-03/processed.1341964800.gz
...etc...
The Data Inputs - Files & Directories screen shows 620 files.
The problem is none of the data ever seems to get indexed, other data in the /data/splunk path does get indexed for other projects. I feel I'm missing one small step, can anyone throw me a bone?
Per @Lamar's request, inputs.conf
[default]
host = wsi-hub
[monitor:///data/splunk/remote]
host_segment = 4
sourcetype = syslog
blacklist = .*.gz
disabled = 0
host =
[monitor://$SPLUNK_HOME/var/log/splunk]
blacklist = *.gz
disabled = false
[monitor:///data/logs/rrsearch]
disabled = false
followTail = 0
host =
host_regex =
index = baseline_search
whitelist = .+processed.+gz$
sourcetype = Baseline Search
host_segment = 4
In indexes:
Index Name: baseline_search
Max Size: 500,000
Frozen Archive: None
Current Size: 3,807
Event Count: 54,237,503
Earliest Event: May 13, 2012 7:59:59 PM
Latest Event: Jul 30, 2012 7:59:59 PM
Home Path: /opt/splunk/var/lib/splunk/baseline_search/db
App: search