Splunk Enterprise

modified inputs.conf in deployment server, pushed to forwarders but splunk serachhead is not retrieving alarms

chrisang
New Member

When tried to add extra path in splunk deployment client (Wildfly logs new):

# Wildfly logs
[monitor:///opt/applications/wildfly/standalone/log/server.log]
sourcetype = jboss_log
disabled = false
followTail = 0
index = newvt_prod
blacklist = .*\.(old|temp|gz|bz2|zip)$

# Wildfly logs new
[monitor:///opt/applications/wildfly/standalone-ext/log/server.log]
sourcetype = jboss_log
disabled = false
followTail = 0
index = newvt_prod
blacklist = .*\.(old|temp|gz|bz2|zip)$

 

and push it to forwarders, the index cannot retrieve any logs from the following path:
/opt/applications/wildfly/standalone-ext/log/server.log

only retrieves from the old path:

/opt/applications/wildfly/standalone/log/server.log

1. checked permissions, they are ok r-x for splunk user
2. checked path and is ok, no mispelling
3. checked index and is growing in size, is not disabled

cannot find any other issue.can someone help?

BR/

CAngel

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Did you restart the forwarders after pushing the new inputs.conf?

---
If this reply helps you, Karma would be appreciated.
0 Karma

chrisang
New Member

Hi,
 
is it possible that the application is disabled so splunk cannot retrieve logs. The directory is there and log is there: "/opt/applications/wildfly/standalone-ext/log/server.log" but the application is not yet functional.
Is splunk checking if the log grow in size and if it not the splunk indexing stops?
 
br/
C.Angel
0 Karma
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...