this is inputs.conf
[monitor://D:\temp\zkstats*.json]
crcSalt = <SOURCE>
disabled = false
followTail = 0
index = abc
sourcetype = zk_stats
props.conf
[zk_stats]
KV_MODE = json
INDEXED_EXTRACTIONS = json
however my search code index=abc sourcetype = zk_stats is not getting new events. meaning to say if zkstats20240824_0700 for example new files coming in it wont re index
1. Check your
splunk list monitor
and
splunk list inputstatus
output
2. Why use crcSalt?
3. Don't use KV_MODE=json when you're using INDEXED_EXTRACTIONS=json and vice versa. (that's not connected to the problem at hand but useful anyway)
How to check the splunk lsit monitor/ where etc
Logs mentions this
08-27-2024 13:00:20.824 +0800 INFO TailingProcessor [32248 MainTailingThread] - Parsing configuration stanza: monitor://D:\temp\zkstats.json.
[sourcetype]
KV_MODE = json
INDEXED_EXTRACTIONS = json
This is my props.conf
I am not able to actually get data in to even consider the crcsalt source
Hi @wm ,
why are you using crcSalt=<SOURCE> ?
It's usually used to reindex already indexed data, usually isn't useful.
try to delete it.
Ciao.
Giuseppe