Getting Data In

Why Monitoring a Directory is not working?

ninisimonishvil
Path Finder

Hello,

I have a folder with several files on desktop. (xml) files have same names but different numbering for ex: File1, File2. File3

I also set up a sourcetype with event breaking that I tested and it is working (if I'm uploading a file having several events)

However when I set Monitor the folder c:\path\File* Choose a sourcetype that I have created, after reviewing I'm directed to search page where there is no single event (I think those files inside my folder are not indexed)

can anyone suggest what can be a reason?

0 Karma

yahuja_splunk
Splunk Employee
Splunk Employee

A sample of the inputs.conf in a windows environment is below.

[monitor://C:\Program Files (x86)\Symantec\Symantec\data\dump\scm_admin.tmp]
sourcetype = symantec:ep:admin:file
index = symantec
disabled = false

make sure you are using the slashes correctly.

0 Karma

ninisimonishvil
Path Finder

[monitor://C:\Users\Administrator\Desktop\Folder\BEX*]

This is my monitoring path.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...