Getting Data In

Splunk universal forwarder isnt sending ONE folder

rtalcik
Path Finder

So I have a seperate folder that was prebuilt from splunk universal forwarder.

The folder path is :

/opt/splunkforwarder/etc/apps/"MY folders HERE"

one of the folders under /apps IS sending

the other folder is not and all it has is a path of

/apps/NOT SENDING FOLDER/local/input.conf

inside inputs.conf I have

[monitor:///var/log/router/.log]
host_regex=router/(.
).log
sourcetype=cisco
index=net
crcSalt=
disabled = 0

this is not monitoring the folder and NO logs are going into splunk

however in the correct folder that is sending i have
[monitor:///var/log/security.log]
sourcetype = seclog
index = sec
disabled = 0

I also have the following folders in the correct logs that i do not have in the no working log

default local metadata README.md static

was wondering if anyone can point me in the direction to help me figure out why one folder is sending but the other isnt.

0 Karma
1 Solution

rtalcik
Path Finder

So i fixed this issue but investigating the errors in splunkd logs like manjuanthemeti said above.

This was resolved by finding out what the issue was and removing empty log files in the directory.

View solution in original post

0 Karma

rtalcik
Path Finder

So i fixed this issue but investigating the errors in splunkd logs like manjuanthemeti said above.

This was resolved by finding out what the issue was and removing empty log files in the directory.

0 Karma

manjunathmeti
Champion

I don't think it's something to do with apps. Configurations looks correct. Check user running splunk process has read permissions to log files in directory /var/log/router/.

If user has read permissions then check for any errors in splunkd logs in /opt/splunkforwarder/var/log/splunk/.

0 Karma

rtalcik
Path Finder

permissions seem fine. they all have root accesss rw both ways

0 Karma

manjunathmeti
Champion

Is root running splunk process? Check splunkd logs /opt/splunkforwarder/var/log/splunk/splunkd.logs and also check if index "net" is created on indexer servers.

0 Karma

rtalcik
Path Finder

very good point I will do.

0 Karma

rtalcik
Path Finder

both have root access

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...