Getting Data In

Not all monitored files being indexed

tkw03
Communicator

we have  monitors on 2 Windows file paths:

[monitor://C:\Data\Data\Disk\SplunkLoad\IsilonCaptures\i*.txt]
index = storage_test
sourcetype = storage:data


[monitor://C:\Data\Data\Disk\SplunkLoad\UnityCaptures\Unity*.csv]
index = storage_test
sourcetype = storage:unity

Filenames like:
i2-20200206.txt

i4-site2-20200129.txt

Unity450-DW-LUNs.csv

Unity450-Open-Pools-Site2.csv

 

The first time after adding these to the app and pushing from the deployment server and having the UF restart it imported MOST of the files except there were a few small, 1 line files. So I de;eted all of the data in the test index and added a crcSalt = <SOURCE> and repushed.  Got the same results. I deleted the data and changed the crcSalt to something different and repushed, pretty much the same results, some but not all files sent for indexing. Now I cannot get it to pull in the files at all.

 

Any thoughts on what might be going on?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...