Getting Data In

Not all monitored files being indexed

tkw03
Communicator

we have  monitors on 2 Windows file paths:

[monitor://C:\Data\Data\Disk\SplunkLoad\IsilonCaptures\i*.txt]
index = storage_test
sourcetype = storage:data


[monitor://C:\Data\Data\Disk\SplunkLoad\UnityCaptures\Unity*.csv]
index = storage_test
sourcetype = storage:unity

Filenames like:
i2-20200206.txt

i4-site2-20200129.txt

Unity450-DW-LUNs.csv

Unity450-Open-Pools-Site2.csv

 

The first time after adding these to the app and pushing from the deployment server and having the UF restart it imported MOST of the files except there were a few small, 1 line files. So I de;eted all of the data in the test index and added a crcSalt = <SOURCE> and repushed.  Got the same results. I deleted the data and changed the crcSalt to something different and repushed, pretty much the same results, some but not all files sent for indexing. Now I cannot get it to pull in the files at all.

 

Any thoughts on what might be going on?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...