Getting Data In

Newly added monitor not being ingested in Splunk

zijian
Explorer

Hi all,

I added a new monitor for a log file in inputs.conf and there were no errors in splunkd.log.

However, it is not being ingested in Splunk, while it worked for other servers.

May I know what configuration settings to check/compare between the problematic server and the working servers?

 

Regards,

Zijian

Labels (3)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

If the inputs.conf was pushed to all servers in an app (which is the way it should be done) then the problem probably lies with the server rather than the Splunk config.  Verify the file exists on all servers and Splunk has read access to it.  If the file doesn't exist then it will be ignored silently; a permissions problem should be logged, but it's easy to miss.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

If the inputs.conf was pushed to all servers in an app (which is the way it should be done) then the problem probably lies with the server rather than the Splunk config.  Verify the file exists on all servers and Splunk has read access to it.  If the file doesn't exist then it will be ignored silently; a permissions problem should be logged, but it's easy to miss.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...