I've recently been running into issues with Splunk not ingesting files, both on universal and heavy forwarders. The example here is a UF on a Windows server. In this example, I'm trying to ingest
\\path\to\file.csv, and the error I get is:
DEBUG TailingProcessor - Skipping itemPath='E:\path\to\some\other\file.txt, does not match path='\\path\to\file.csv' :Not a directory :Not a symlink
My input looks like:
[monitor://\\\\path\to\file.csv] index = myindex sourcetype = mysourcetype initCrcLength = 512
Also, I had to turn on debug logging in log.cfg to even see these errors. Otherwise there were no errors at all.
Same here, the UF was working fine on a Windows server than suddenly started to not ingest the file anymore. To see the error I had to put in debug mode the universal forwarder. The strange thing is that other files are still monitored and forwarded correctly.
I have even added followSymlink=false and CHECK_METHOD=modtime without any luck
disabled=0 index=myindex sourcetype=mysourcetype crcSalt = <SOURCE>