Splunk Search

Monitor a file or directory indexing no longer working

hoffmandirt
Explorer

The "monitor a file or directory" data input option is no longer working. When I add a new file this way, the source nor the source type show up in the Search application. I can't run any queries against the sources. What would be causing this? My free trial license recently expired, but I don't think that's the issue. I am using Splunk v4.1.5.


I found this in the $SPLUNK_HOME\etc\system\default\indexes.conf file:

[main]
homePath   = $SPLUNK_DB\defaultdb\db
coldPath   = $SPLUNK_DB\defaultdb\colddb
thawedPath = $SPLUNK_DB\defaultdb\thaweddb
maxMemMB = 20
maxConcurrentOptimizes = 6
maxHotIdleSecs = 86400
maxHotBuckets = 10
maxDataSize = auto_high_volume

Whats the maxMemMB property? That index is currently 22mb in size. Also I created a new index and the monitor file option worked as expected. Thoughts?

Tags (2)
0 Karma

Simeon
Splunk Employee
Splunk Employee

Unless you convert to the free version of Splunk, you may be experiencing searches getting disabled. You should check your license status (in the manager portion of the UI) to see the status of your license. Also, it might be possible you are sending data to an index that is not shown in the summary page by default.

Get Updates on the Splunk Community!

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

Unlock Instant Security Insights from Amazon S3 with Splunk Cloud — Try Federated ...

Availability: Must be on Splunk Cloud Platform version 10.1.2507.x to view the free trial banner. If you are ...