Getting Data In

Why I don't see newly indexed files in the "Data inputs » Files & directories" menu

VaultTec
Engager

Hello Everyone!

I'm a newbie and have a newbie question:

I've added few log files to be indexed via the Data inputs » Files & directories menu, and I don't see them in the list.
I manage to search these files without any problem, but when I wanna check the list of files I indexed so far I don't have a way to do it,
since the Data inputs » Files & directories menu is not being updated.

Any ideas?

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

You can run this search:

| metadata type=sources index=*

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

You can run this search:

| metadata type=sources index=*

VaultTec
Engager

It works.
Thank you!

0 Karma

VaultTec
Engager

Thank you for your comment someoni2!

Just indexed once, is that the reason?
If so is there a way to see the files I indexed so far?

Dan.

0 Karma

somesoni2
Revered Legend

Did you add the data input to monitor them continuously or just indexed once? (The last screen in the add file data menu has radio buttons for these options)

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...