Getting Data In

Newly added monitor not being ingested in Splunk

zijian
Explorer

Hi all,

I added a new monitor for a log file in inputs.conf and there were no errors in splunkd.log.

However, it is not being ingested in Splunk, while it worked for other servers.

May I know what configuration settings to check/compare between the problematic server and the working servers?

 

Regards,

Zijian

Labels (3)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

If the inputs.conf was pushed to all servers in an app (which is the way it should be done) then the problem probably lies with the server rather than the Splunk config.  Verify the file exists on all servers and Splunk has read access to it.  If the file doesn't exist then it will be ignored silently; a permissions problem should be logged, but it's easy to miss.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

If the inputs.conf was pushed to all servers in an app (which is the way it should be done) then the problem probably lies with the server rather than the Splunk config.  Verify the file exists on all servers and Splunk has read access to it.  If the file doesn't exist then it will be ignored silently; a permissions problem should be logged, but it's easy to miss.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...