I have added a data input that uses variables as the host name, so /opt/mark/home/.../.../logs
It uses segment 5 as the host, and it's picking up 12 of them, but it's missing a few of them.
Solution found; Splunk data inputs are case sensitive. Was missing a capital letter.
View solution in original post