Getting Data In

Not all monitored files being indexed

Communicator

we have  monitors on 2 Windows file paths:

[monitor://C:\Data\Data\Disk\SplunkLoad\IsilonCaptures\i*.txt]
index = storage_test
sourcetype = storage:data


[monitor://C:\Data\Data\Disk\SplunkLoad\UnityCaptures\Unity*.csv]
index = storage_test
sourcetype = storage:unity

Filenames like:
i2-20200206.txt

i4-site2-20200129.txt

Unity450-DW-LUNs.csv

Unity450-Open-Pools-Site2.csv

 

The first time after adding these to the app and pushing from the deployment server and having the UF restart it imported MOST of the files except there were a few small, 1 line files. So I de;eted all of the data in the test index and added a crcSalt = <SOURCE> and repushed.  Got the same results. I deleted the data and changed the crcSalt to something different and repushed, pretty much the same results, some but not all files sent for indexing. Now I cannot get it to pull in the files at all.

 

Any thoughts on what might be going on?

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!