Getting Data In

Newly added monitor not being ingested in Splunk

zijian
Explorer

Hi all,

I added a new monitor for a log file in inputs.conf and there were no errors in splunkd.log.

However, it is not being ingested in Splunk, while it worked for other servers.

May I know what configuration settings to check/compare between the problematic server and the working servers?

 

Regards,

Zijian

Labels (3)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

If the inputs.conf was pushed to all servers in an app (which is the way it should be done) then the problem probably lies with the server rather than the Splunk config.  Verify the file exists on all servers and Splunk has read access to it.  If the file doesn't exist then it will be ignored silently; a permissions problem should be logged, but it's easy to miss.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

If the inputs.conf was pushed to all servers in an app (which is the way it should be done) then the problem probably lies with the server rather than the Splunk config.  Verify the file exists on all servers and Splunk has read access to it.  If the file doesn't exist then it will be ignored silently; a permissions problem should be logged, but it's easy to miss.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...