Getting Data In

What could prevent the monitoring of papercut logs?

dspencer
Engager
  • I'm collecting all other logs ie. wineventlogs, splunkd logs
  • the inputs.conf is accurate
  • the splunk user has full access to the file

 

What are some non-splunk reasons that would prevent a file from being monitored?

Labels (2)
0 Karma

marnall
Motivator

Can you search the internal index, specifically splunkd, to be sure that your configuration stanza is being parsed and that the TailingProcessor is adding a watch on the file path?

E.g.

index=_internal source="/opt/splunk/var/log/splunk/splunkd.log" <logfilename>


0 Karma
Get Updates on the Splunk Community!

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

Unlock Instant Security Insights from Amazon S3 with Splunk Cloud — Try Federated ...

Availability: Must be on Splunk Cloud Platform version 10.1.2507.x to view the free trial banner. If you are ...