The "monitor a file or directory" data input option is no longer working. When I add a new file this way, the source nor the source type show up in the Search application. I can't run any queries against the sources. What would be causing this? My free trial license recently expired, but I don't think that's the issue. I am using Splunk v4.1.5.
I found this in the $SPLUNK_HOME\etc\system\default\indexes.conf file:
[main]
homePath = $SPLUNK_DB\defaultdb\db
coldPath = $SPLUNK_DB\defaultdb\colddb
thawedPath = $SPLUNK_DB\defaultdb\thaweddb
maxMemMB = 20
maxConcurrentOptimizes = 6
maxHotIdleSecs = 86400
maxHotBuckets = 10
maxDataSize = auto_high_volume
Whats the maxMemMB property? That index is currently 22mb in size. Also I created a new index and the monitor file option worked as expected. Thoughts?
Unless you convert to the free version of Splunk, you may be experiencing searches getting disabled. You should check your license status (in the manager portion of the UI) to see the status of your license. Also, it might be possible you are sending data to an index that is not shown in the summary page by default.