Splunk Search

Monitor a file or directory indexing no longer working

hoffmandirt
Explorer

The "monitor a file or directory" data input option is no longer working. When I add a new file this way, the source nor the source type show up in the Search application. I can't run any queries against the sources. What would be causing this? My free trial license recently expired, but I don't think that's the issue. I am using Splunk v4.1.5.


I found this in the $SPLUNK_HOME\etc\system\default\indexes.conf file:

[main]
homePath   = $SPLUNK_DB\defaultdb\db
coldPath   = $SPLUNK_DB\defaultdb\colddb
thawedPath = $SPLUNK_DB\defaultdb\thaweddb
maxMemMB = 20
maxConcurrentOptimizes = 6
maxHotIdleSecs = 86400
maxHotBuckets = 10
maxDataSize = auto_high_volume

Whats the maxMemMB property? That index is currently 22mb in size. Also I created a new index and the monitor file option worked as expected. Thoughts?

Tags (2)
0 Karma

Simeon
Splunk Employee
Splunk Employee

Unless you convert to the free version of Splunk, you may be experiencing searches getting disabled. You should check your license status (in the manager portion of the UI) to see the status of your license. Also, it might be possible you are sending data to an index that is not shown in the summary page by default.

Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...