Getting Data In

Simple text file suddenly (but thoroughly) being ignored

mikeely
Path Finder

I've got this little file Oracle appends a row to every hour, and it stopped being monitored mysteriously sometime around the last logrotate (near as I can tell). Now it's not updating, or updating haphazardly. Here's what the file looks like:

10-01-12:08:47:02,         0,         0,         2,         6,       106,         2
10-01-12:08:48:01,         0,         0,         2,         6,       106,         2
10-01-12:08:49:01,         0,         0,         2,         6,       106,         2

Heady stuff, I know. Anyhow, Splunk was indexing that file well enough and now it isn't. Currently, my inputs.conf stanza for it looks like this:

[monitor:///u01/app/oracle/db/tech_st/11.1.0/log/scriptout]

recursive = true

disabled=0

followTail=1

I've tried crcSalt to no avail. I even tried to disable followTail but in the log it said TailingProcessor: starting at offset whatever... and continued to not do what I wanted.

Is there a way to "reset" the entries resulting from this stanza and force a re-index? And why did it die?

0 Karma

woodcock
Esteemed Legend
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...