Hi all,
I added a new monitor for a log file in inputs.conf and there were no errors in splunkd.log.
However, it is not being ingested in Splunk, while it worked for other servers.
May I know what configuration settings to check/compare between the problematic server and the working servers?
Regards,
Zijian
If the inputs.conf was pushed to all servers in an app (which is the way it should be done) then the problem probably lies with the server rather than the Splunk config. Verify the file exists on all servers and Splunk has read access to it. If the file doesn't exist then it will be ignored silently; a permissions problem should be logged, but it's easy to miss.
If the inputs.conf was pushed to all servers in an app (which is the way it should be done) then the problem probably lies with the server rather than the Splunk config. Verify the file exists on all servers and Splunk has read access to it. If the file doesn't exist then it will be ignored silently; a permissions problem should be logged, but it's easy to miss.