Splunk Enterprise

modified inputs.conf in deployment server, pushed to forwarders but splunk serachhead is not retrieving alarms

chrisang
New Member

When tried to add extra path in splunk deployment client (Wildfly logs new):

# Wildfly logs
[monitor:///opt/applications/wildfly/standalone/log/server.log]
sourcetype = jboss_log
disabled = false
followTail = 0
index = newvt_prod
blacklist = .*\.(old|temp|gz|bz2|zip)$

# Wildfly logs new
[monitor:///opt/applications/wildfly/standalone-ext/log/server.log]
sourcetype = jboss_log
disabled = false
followTail = 0
index = newvt_prod
blacklist = .*\.(old|temp|gz|bz2|zip)$

 

and push it to forwarders, the index cannot retrieve any logs from the following path:
/opt/applications/wildfly/standalone-ext/log/server.log

only retrieves from the old path:

/opt/applications/wildfly/standalone/log/server.log

1. checked permissions, they are ok r-x for splunk user
2. checked path and is ok, no mispelling
3. checked index and is growing in size, is not disabled

cannot find any other issue.can someone help?

BR/

CAngel

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Did you restart the forwarders after pushing the new inputs.conf?

---
If this reply helps you, Karma would be appreciated.
0 Karma

chrisang
New Member

Hi,
 
is it possible that the application is disabled so splunk cannot retrieve logs. The directory is there and log is there: "/opt/applications/wildfly/standalone-ext/log/server.log" but the application is not yet functional.
Is splunk checking if the log grow in size and if it not the splunk indexing stops?
 
br/
C.Angel
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...