- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
File Monitor configured - but nothing is indexing ?
here is my inputs.conf
[monitor://C:\xxxx\xxxxxx\xxxxxxx\xxxxx.docx]
[monitor://C:\xxxxx\xxxxxxx\xxxxxx.docx]
disabled = 0
index=file_integrity_monitoring
sourcetype=test
crcSalt=<SOURCE>
following the article below in our Splunk Cloud environment.
https://docs.splunk.com/Documentation/Splunk/8.2.1/Data/Monitorfilesanddirectorieswithinputs.conf
Any idea what is missing ?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


First, having two consecutive [monitor://...] lines does not create two monitors with the same settings. The first monitor uses only default settings, whereas the second uses those specified in the stanza.
Second, check splunkd.log to confirm it, but I suspect nothing is ingested because .docx files are binary and Splunk doesn't ingest non-textual data.
Finally, it looks like you want to detect when these files change rather than index the files themselves. If so, use an fschange input. See https://docs.splunk.com/Documentation/Splunk/8.2.1/Data/Monitorchangestoyourfilesystem
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


First, having two consecutive [monitor://...] lines does not create two monitors with the same settings. The first monitor uses only default settings, whereas the second uses those specified in the stanza.
Second, check splunkd.log to confirm it, but I suspect nothing is ingested because .docx files are binary and Splunk doesn't ingest non-textual data.
Finally, it looks like you want to detect when these files change rather than index the files themselves. If so, use an fschange input. See https://docs.splunk.com/Documentation/Splunk/8.2.1/Data/Monitorchangestoyourfilesystem
If this reply helps you, Karma would be appreciated.
