Getting Data In

Why is Splunk not reading existing files from same server?

ram254481493
Explorer

Hi

Currently, I have setup inputs.conf, Splunk is reading all the directories in the inputs file- but not reading one file.
I tried using crcSalt but nothing works.
It's reading first 3 monitor paths but not reading the last one.
All three are from the same server and the log exists.

[monitor://D:\Talx.xxx\EDRService.xxxx\AppLogs*]
disabled = false
recursive = false
index = xxxxxx
sourcetype = xxxxxx

[monitor://D:\AuditAndxxxxxx\TWNEmployerServiceP0xxxxxx.trace.*]
disabled = false
recursive = false
index = xxxxx
sourcetype = xxxxxx

[monitor://D:\AuditAndxxxxx\TWNEmployerxxxxx.*]
disabled = false
recursive = false
index = xxxxx
sourcetype = xxxxxx

[monitor://D:\Talx.xxxxxxx\TWNEmployer.xxxxxx_Logs\AppLogs.*]
disabled = false
recursive = false
index = pxxxxxx
crcSalt = 
sourcetype = xxxxxxxxxxx
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Verify Splunk has read access to the directories and files it is to monitor.
Check splunkd.log for related error messages.
Run splunk btool --debug inputs list to verify the configuration.
Run splunk list monitor to verify what Splunk is monitoring.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Verify Splunk has read access to the directories and files it is to monitor.
Check splunkd.log for related error messages.
Run splunk btool --debug inputs list to verify the configuration.
Run splunk list monitor to verify what Splunk is monitoring.

---
If this reply helps you, Karma would be appreciated.

ram254481493
Explorer

sure thanks for your help it was a issue with my monitoring stanza. And its resolved.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

To help future readers, please add and accept an answer explaining how you resolved the problem.

---
If this reply helps you, Karma would be appreciated.
0 Karma

ram254481493
Explorer

hi i am not able to accept the answer , i cannot see the accept answer button. In my monitoring path i had an extra space so its not reading the logs , i removed the extra space and i restart the forwarder , it starts flowing the logs.

0 Karma

ram254481493
Explorer

Thanks now i am able to do it

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...