Getting Data In

What could prevent the monitoring of papercut logs?

dspencer
Loves-to-Learn
  • I'm collecting all other logs ie. wineventlogs, splunkd logs
  • the inputs.conf is accurate
  • the splunk user has full access to the file

 

What are some non-splunk reasons that would prevent a file from being monitored?

Labels (2)
0 Karma

marnall
Builder

Can you search the internal index, specifically splunkd, to be sure that your configuration stanza is being parsed and that the TailingProcessor is adding a watch on the file path?

E.g.

index=_internal source="/opt/splunk/var/log/splunk/splunkd.log" <logfilename>


0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...