Getting Data In

TCP_ROUTING Sub-folders of monitors fails

efo
Engager

Hi,
Monitoring subfolders of other monitors while using TCP_ROUTING results in subfolders not being indexed.
Do anyone of you have any experiences with this, or possible workarounds? 🙂

Removing the /var/log monitor will get data into to the customer01 and customer02 servers, so i know that the ROUTING is working.

Adding additional TCP_ROUTING to /var/log/ do not seem to help.

[monitor:///var/log/customer]
disabled=false
index=index1y
blacklist=.(gz|\d+)$
recursive=false
_TCP_ROUTING=customer01,customer02

[monitor:///var/log]
disabled = false
blacklist = (.(gz|bz2|z|zip)|lastlog|wtmp|btmp)$
followTail = 1
recursive = false

--
Best regards
Espen

0 Karma

elof
Path Finder

I guess you stumbled on the same "bug" as I did.
This was my workaround:
http://answers.splunk.com/answers/126064/bug-in-universal-forwarder-inputsconf-monitor-and-recursive...

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...