Monitoring Splunk

How to check status of indexing?

pradjswl
Explorer

I am using splunk-enterprise in my local machine. I have configured 4 Files/Directory monitoring for the data indexing. I added one file in all of the directory. I dont see the data from 4ht directory getting indexed and shown in splunk result. Thought i do see the data from other 3 directory getting indexed and displayed in search result. Is there a way I can check the status if the data from that directory is really indexed or not . I am looking for an approach other than searching for that data in search query, as I already know the search is not returning the result from that source type.

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Since you have 3 of the 4 directories indexed we can monitoring is working correctly. That means either 1) the monitor settings for the 4th directory are incorrect; or 2) the query searching for directory 4 is incorrect. Double-check your monitor settings and compare them to your query.

---
If this reply helps you, Karma would be appreciated.
0 Karma

DalJeanis
Legend

I'd also carefully check the conf settings for the fourth source type and see if any values have not been updated correctly.

I'd also do a quick search to see if maybe the results WAS indexed, but was marked with the wrong sourcetype...

(a search that returns one specific record from the test file) 
| stats count as totalcount dc(sourcetype) as distinctcount by _raw
0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...