Monitoring Splunk

Splunk file monitoring issue

uagraw01
Motivator
walmart_2.xml

walmart_3.xml

walmart_4.xml

Scenerio I

 

When using below configuration in Inputs.conf we can able to monitor in splunk
 

[monitor://D:\scada_server\walmart_2.xml]

disabled = false

host = WALVAU-VIDI-1

index = 2313917_2797418_scada

sourcetype = Scada_walmart_alarm

crcSalt = <SOURCE>

CHECK_METHOD = entire_md5

 

Scenerio 2

 

Hello Splunkers!!

I need your help to fix this issue.
When using below configuration in Inputs.conf we can't able to monitor in splunk.

 

[monitor://D:\scada_server\walmart_*.xml]

disabled = false

host = WALVAU-VIDI-1

index = 2313917_2797418_scada

sourcetype = Scada_walmart_alarm

crcSalt = <SOURCE>

CHECK_METHOD = entire_md5

 

Please suggest some workaround.

0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@uagraw01 Hello, All files with the.xml extension, such as /scada_server/walmart_1.xml, /scada_server/walmart_2.xml, /scada_server/walmart_3.xml, and so forth, are matched by /walmart_*.xml. Could you please verify the permissions for every file inside this directory?And also,  You can try to remove the CrCSalt and try. 

Check the below document for more examples: 

https://docs.splunk.com/Documentation/Splunk/latest/Data/Specifyinputpathswithwildcards 

 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @uagraw01,

sorry but I don't understand your question, anyway, then, why do are using crcSalt=<SOURCE>?

please try this:

[monitor://D:\scada_server\walmart_*.xml]
disabled = false
host = WALVAU-VIDI-1
index = 2313917_2797418_scada
sourcetype = Scada_walmart_alarm
CHECK_METHOD = entire_md5

Then why are you using a so complex index?

Ciao.

Giuseppe

0 Karma

uagraw01
Motivator

@gcusello @kiran_panchavat I have permission on the directory as well. I tried without using crcSalt as well. But no luck was found.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...