Splunk Search

Issue with conitnously monitoring a folder

deepthi5
Path Finder

Hi Team
I have a folder that consists of logs added every day i have given this folder as input to splunk to continuously monitor the folder and do few actions as per the search query but splunk is not picking up the newly indexed data but when i append the new data to existing files splunk starts picking up can anyone help me with this

Thanks and Regards,
Deepthi bulusu

Tags (3)
0 Karma

lagnone_splunk
Splunk Employee
Splunk Employee

Deepthi,

Are you sure that your monitor stanza is picking up the new files?
Is it only monitoring a folder? Check the splunkd.log for details on what tailing processor is doing.

For more details
1) Go to the splunk forwarder installation and edit the $SPLUNK_HOME/etc/log.cfg
2) Find these components and change them to DEBUG
TailingProcessor. BatchReader, WatchedFile
3) Restart the forwarder
4) Look for which files are being read

You can also hit the REST endpoint at port 8089 and look at file input status

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...