Getting Data In

addition of log files to already configured input path

spatil
Path Finder

Hi ,

I have below configuration in inputs .conf [monitor:C:\Program Files\Splunk\etc\apps\sampleApp\samplelogs]

I have 2 folders containing csv log files under sampleLogs. Thsese folders are already indexed.

Now, I added one more folder containing log files (say sample3)under samplelogs folder. I restarted splunk to get newly added files indexed. But, those newly added files are not indexed. Index size and number of events for index is still same.

What is the wrong here ? How can I add new input files to already indexed folder?

regards. S

Tags (2)
0 Karma
1 Solution

spatil
Path Finder

solved. Added below line in inputs.conf crcSalt =C:\Program Files\Splunk\etc\apps\sampleApp\samplelogs

"C:\Program Files\Splunk\etc\apps\sampleApp\samplelogs" is source for log files

Regards, S.

View solution in original post

0 Karma

spatil
Path Finder

solved. Added below line in inputs.conf crcSalt =C:\Program Files\Splunk\etc\apps\sampleApp\samplelogs

"C:\Program Files\Splunk\etc\apps\sampleApp\samplelogs" is source for log files

Regards, S.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...