Getting Data In

Not all monitored files being indexed

tkw03
Communicator

we have  monitors on 2 Windows file paths:

[monitor://C:\Data\Data\Disk\SplunkLoad\IsilonCaptures\i*.txt]
index = storage_test
sourcetype = storage:data


[monitor://C:\Data\Data\Disk\SplunkLoad\UnityCaptures\Unity*.csv]
index = storage_test
sourcetype = storage:unity

Filenames like:
i2-20200206.txt

i4-site2-20200129.txt

Unity450-DW-LUNs.csv

Unity450-Open-Pools-Site2.csv

 

The first time after adding these to the app and pushing from the deployment server and having the UF restart it imported MOST of the files except there were a few small, 1 line files. So I de;eted all of the data in the test index and added a crcSalt = <SOURCE> and repushed.  Got the same results. I deleted the data and changed the crcSalt to something different and repushed, pretty much the same results, some but not all files sent for indexing. Now I cannot get it to pull in the files at all.

 

Any thoughts on what might be going on?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...