Getting Data In

Why is Splunk not indexing all files in all folders on Amazon S3?


I have set up an S3 bucket and added it as a data input source. I started with one folder in the bucket and it indexed all files OK. I then added two more folders an again it is indexing all the incoming files OK. But I have now added a further 18 folders which all have files pushed to them every 15 secs but splunk is not indexing them. I am using the trial account. Please could you help me?

Many thanks

Tags (2)
0 Karma

Splunk Employee
Splunk Employee

A sample of your inputs.conf would help here. I have a feeling that you haven't leveraged whitelists and may have overlapping stanzas.

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!