Getting Data In
Highlighted

Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?

Engager

Hi Everyone,

I'm looking to monitor some files locally on the Splunk instance, and I am able to add them as data inputs. However, this monitoring does not seem to be continuous; it logs those files once and then doesn't continue to monitor them even as data is added. Am I doing something wrong? How do I get these to monitor changes to the files? Thanks very much!

This is a Splunk for Windows instance running on Windows 2008 R2.

0 Karma
Highlighted

Re: Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?

Motivator

hi,
these are the windows files?

0 Karma
Highlighted

Re: Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?

Engager

Yes, I'm sorry -- just edited. These are Windows files. The Splunk Enterprise instance is installed on a Windows 2008 R2 server. These files are stored locally.

0 Karma
Highlighted

Re: Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?

Builder

HI,
when you choose "continuously indexing a file", the path of that file and the name of the file must not change. If one of them change, splunk'll not be able to index that file.
If you respect those conditions and your index file is heavy, be patien because i had files that take me more than 45 mn to be indexed

0 Karma
Highlighted

Re: Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?

Engager

Hi Noumssi,

Where is the "continuously indexing a file" option? I think that's my problem; I can't find that option in Splunk. I am not changing the file name and I have waited 24 hours.

0 Karma
Highlighted

Re: Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?

Builder

which version of splunk do you use?

0 Karma
Highlighted

Re: Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?

Engager

This is splunk 6.2.

0 Karma
Highlighted

Re: Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?

Builder

ok
1. click on add data
2. click on monitor
3. files & directories
4. give the path and then click on continuously monitor

0 Karma
Highlighted

Re: Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?

Engager

Thanks Noum, I see it now. I think, however, that option was already chosen. Now I have to figure out why it's not actually updating.

0 Karma
Highlighted

Re: Monitoring files on a local Windows 2008 R2 server, why aren't new files getting indexed?

Builder

make sure that this option is choosed and wait sometime, the updating'll be done

0 Karma