I have set up an S3 bucket and added it as a data input source. I started with one folder in the bucket and it indexed all files OK. I then added two more folders an again it is indexing all the incoming files OK. But I have now added a further 18 folders which all have files pushed to them every 15 secs but splunk is not indexing them. I am using the trial account. Please could you help me?
Many thanks
A sample of your inputs.conf would help here. I have a feeling that you haven't leveraged whitelists and may have overlapping stanzas.