Monitoring Splunk

Data preview option is missing

htidore
Path Finder

My environment is Splunk version 7.01 on MacOS Sierra.

When I try to monitor a folder (during configuration Settings > Data Inputs > Files and Directories), it gives me an error :

alt text

I only start having this problem after upgrading my laptop to MacOS Sierra with APFS. I have also entered the following line into $SPLUNK_HOME/etc/splunk-launch.conf
OPTIMISTIC_ABOUT_FILE_LOCKING = 1
Without the above entry, Splunk cannot start.

My question is how come Data preview is skipped? Any way to fix this problem?

Thanks.
Hanny.

0 Karma

mattymo
Splunk Employee
Splunk Employee

Hi htidore!

Glad to see you using add data wizard. It is a very useful way to ensure you build your sourcetypes right!

As the warning explicitly advises, data preview is skipped for directories. It has been this way as long as I can remember. It is not an issue, it is expected behavior. It cannot traverse multiple directories/deal with multiple files at once. You can still build the input this way, just can't test your props.

If you are trying to use it to build props, the best way around it is to start the data wiz as if you are working with a single file in the dir, navigate to a single file, set up the props the way you want, then use the "copy to clipboard" option to save the props settings you need, then cancel out of the wizard.

You can then go back thru the wizard to enable the input if you need to, after you put your props in the correct app.

- MattyMo
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...