Getting Data In

no events after add directory monitor

tissparkle
Explorer

I had created a file: input.conf with the following information
[monitor:C:\splun_new\log.csv]
index=1974
sourcetype=csv
in the manager path -> input data - file and direcotry
it was been created the new data input with the correct index
but if i see in a index tab I had 0 indexed events
pelase help me to find out what was wrong.
thanks

Tags (3)
0 Karma
1 Solution

rroberts
Splunk Employee
Splunk Employee

Well, the monitor stanza syntax is prepended with 2 forward slashes:

[monitor://C:\mylog.file]

From http://docs.splunk.com/Documentation/Splunk/5.0.3/admin/Inputsconf

[monitor://]

* This directs Splunk to watch all files in .

View solution in original post

rroberts
Splunk Employee
Splunk Employee

Well, the monitor stanza syntax is prepended with 2 forward slashes:

[monitor://C:\mylog.file]

From http://docs.splunk.com/Documentation/Splunk/5.0.3/admin/Inputsconf

[monitor://]

* This directs Splunk to watch all files in .

asimagu
Builder

can you provide more info?

is that the real path to the file?

0 Karma
Get Updates on the Splunk Community!

Splunk Certification Support Alert | Pearson VUE Outage

Splunk Certification holders and candidates!  Please be advised of an upcoming system maintenance period for ...

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...