Monitoring Splunk

Monitoring a text file Issue

Channu
New Member

I am trying to extract some information from a text file. This is how my inputs.conf looks like,

[monitor://C:\Temp\ServerInfo_Tag.txt]
sourcetype = ABC
index = filelog
crcSalt =

I pushed this config across 4000 windows servers. Ideally Splunk should pickup the file content as soon as the config is pushed.

But strange thing here is, I can see the file content as an event on Splunk for ONLY 3000 servers.
For the other 1000 servers I have to modify the file to get the file content on Splunk.

Is there a way to get the file content without modifying the file?

Config doesn't seem to be an issue here as it it working for other servers and there are no port related issues on the other 1000 servers as I can see the data on Splunk after modifying the file.

Any suggestions here are highly appreciated.

Thanks,
Channesh

Tags (1)
0 Karma

somesoni2
Revered Legend

I would check splunkd.log (index=_internal sourcetype=splunkd host=yourWinServer) for errors for the file. Are you restarting splunk on your windows servers after pushing the configurations (handled by restartSplunkd attribute on serverclass.conf)?

0 Karma

Channu
New Member

@somesoni2 Log has this information which is hard to understand.
03-12-2019 11:21:56.938 -0400 INFO TailingProcessor - Parsing configuration stanza: monitor://C:\CWXTI\ServerInfo_Tag.txt.
03-12-2019 11:21:56.938 -0400 INFO TailReader - State transitioning from 1 to 0 (initOrResume).
03-12-2019 11:21:56.938 -0400 INFO TailReader - State transitioning from 1 to 0 (initOrResume).
03-12-2019 11:21:56.938 -0400 INFO TailingProcessor - Adding watch on path: C:\CWXTI\ServerInfo_Tag.txt.

Yes, servers are being restarted after pushing the configurations.

0 Karma

Channu
New Member

@somesoni2 I could these logs related to the file I am monitoring.
03-12-2019 11:21:56.938 -0400 INFO TailingProcessor - Parsing configuration stanza: monitor://C:\CWXTI\ServerInfo_Tag.txt.
03-12-2019 11:21:56.938 -0400 INFO TailingProcessor - Parsing configuration stanza: monitor://C:\Program Files\CernerESM\sentinel\sentinel.config.
03-12-2019 11:21:56.938 -0400 INFO TailReader - State transitioning from 1 to 0 (initOrResume).
03-12-2019 11:21:56.938 -0400 INFO TailReader - State transitioning from 1 to 0 (initOrResume).
03-12-2019 11:21:56.938 -0400 INFO TailingProcessor - Adding watch on path: C:\CWXTI\ServerInfo_Tag.txt.

0 Karma

Channu
New Member

[monitor://C:\CWXTI\ServerInfo_Tag.txt]
crcSalt =
sourcetype = SENT
index = wineventlog

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...