Getting Data In

file and folder monitoring NOT indexing

cpuppet
Path Finder

I know many people had asked this questions, but I still can't seem to find a good way to solve this problem

I have setup my splunk to monitor several folders
this my inputs.conf sample
[monitor:///opt/splunk/etc/apps/app_name/logs/folder/logfile*]
index = myindex
sourcetype = my.log

I even put crcSalt = to try
but it is still not indexing my logs correctly
and when i look at the data inputs monitoring page
http://localhost:8000/en-US/manager/app_name/data/inputs/monitor

I found that the number of file counts are incorrect

anyone!!! please enlighten me

Tags (1)
0 Karma
1 Solution

kristian_kolb
Ultra Champion

Hi, I don't know if your inputs.conf above is just an example, or the actual configuration. If the latter is the case... well you cannot monitor files under /opt/splunk/etc, since they are automatically watched over by fschange and, (as you may remember from the documentation on inputs.conf) you can't use fschange and monitor on the same files/directories.

See the documentation for inputs.conf
http://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf

hope this helps,

Kristian

View solution in original post

kristian_kolb
Ultra Champion

Hi, I don't know if your inputs.conf above is just an example, or the actual configuration. If the latter is the case... well you cannot monitor files under /opt/splunk/etc, since they are automatically watched over by fschange and, (as you may remember from the documentation on inputs.conf) you can't use fschange and monitor on the same files/directories.

See the documentation for inputs.conf
http://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf

hope this helps,

Kristian

cpuppet
Path Finder

it was an example, but i think i found the problem.
thanks a lot for the info shared

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...