Splunk stopped following data input files for changes.
This happend after I was accessing https://splunk-server:8089/services/* and https://splunk-server:8089/servicesNS/* and trying to reload configuration (after editing times.conf)
Now new log events are indexed only after splunk restart. Stopping splunk takes over 7 minutes. Previous shut down time was about 1 minute.
It's not a space issue. System has 400GB available. Splunk version is 4.1.
... View more