Getting Data In

Newly added monitor not being ingested in Splunk

zijian
Explorer

Hi all,

I added a new monitor for a log file in inputs.conf and there were no errors in splunkd.log.

However, it is not being ingested in Splunk, while it worked for other servers.

May I know what configuration settings to check/compare between the problematic server and the working servers?

 

Regards,

Zijian

Labels (3)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

If the inputs.conf was pushed to all servers in an app (which is the way it should be done) then the problem probably lies with the server rather than the Splunk config.  Verify the file exists on all servers and Splunk has read access to it.  If the file doesn't exist then it will be ignored silently; a permissions problem should be logged, but it's easy to miss.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

If the inputs.conf was pushed to all servers in an app (which is the way it should be done) then the problem probably lies with the server rather than the Splunk config.  Verify the file exists on all servers and Splunk has read access to it.  If the file doesn't exist then it will be ignored silently; a permissions problem should be logged, but it's easy to miss.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...