Let's start with some basic data feed troubleshooting:
any messages in splunkd.log confirming the forwarder has started to monitor that folder?
are you sure permissions on those files are correct for splunk to be able to read them?
any errors in splunkd.log on that forwarder related to this feed?
what does the forwarder's metrics.log say about this sourcetype?
what do your indexer metrics.log say about this sourcetype?
have your tried searching for 'all time', in case time stamp extraction isn't working perfectly?
... View more