Getting Data In

no events after add directory monitor

Explorer

I had created a file: input.conf with the following information
[monitor:C:\splun_new\log.csv]
index=1974
sourcetype=csv
in the manager path -> input data - file and direcotry
it was been created the new data input with the correct index
but if i see in a index tab I had 0 indexed events
pelase help me to find out what was wrong.
thanks

Tags (3)
0 Karma
1 Solution

Splunk Employee
Splunk Employee

Well, the monitor stanza syntax is prepended with 2 forward slashes:

[monitor://C:\mylog.file]

From http://docs.splunk.com/Documentation/Splunk/5.0.3/admin/Inputsconf

[monitor://]

* This directs Splunk to watch all files in .

View solution in original post

Splunk Employee
Splunk Employee

Well, the monitor stanza syntax is prepended with 2 forward slashes:

[monitor://C:\mylog.file]

From http://docs.splunk.com/Documentation/Splunk/5.0.3/admin/Inputsconf

[monitor://]

* This directs Splunk to watch all files in .

View solution in original post

Builder

can you provide more info?

is that the real path to the file?

0 Karma