Hi @kpcool, if sometimes you take logs and sometimes not, you have a correct input configuration. Now we have to check why, sometimes not! Please check if the times that you don't index files, the content of the file is the same of the previous one (also with a different filename), because Splunk by default doesn't index twice a log also if in different files. If this is your situation, you have to add to your inputs.conf stanza: crcSalt = <SOURCE> In this way splunk index all the files with different filename. ciao. Giuseppe
... View more