Getting Data In

Newly added monitor not being ingested in Splunk

zijian
Explorer

Hi all,

I added a new monitor for a log file in inputs.conf and there were no errors in splunkd.log.

However, it is not being ingested in Splunk, while it worked for other servers.

May I know what configuration settings to check/compare between the problematic server and the working servers?

 

Regards,

Zijian

Labels (3)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

If the inputs.conf was pushed to all servers in an app (which is the way it should be done) then the problem probably lies with the server rather than the Splunk config.  Verify the file exists on all servers and Splunk has read access to it.  If the file doesn't exist then it will be ignored silently; a permissions problem should be logged, but it's easy to miss.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

If the inputs.conf was pushed to all servers in an app (which is the way it should be done) then the problem probably lies with the server rather than the Splunk config.  Verify the file exists on all servers and Splunk has read access to it.  If the file doesn't exist then it will be ignored silently; a permissions problem should be logged, but it's easy to miss.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...