I'm having an issue with one of my monitored paths. Here's the monitor stanza, the blacklist line should only blacklist one file in a directory of about 420 log files:
[monitor:///logs/reg*/last/...] sourcetype = xxxx:Regional blacklist = xxxx_\d{4}-\d{2}-\d{2}\.log index = xxxx disabled = false crcSalt = <SOURCE>
The output of splunk list monitor shows me all the files I expect to see based on the above stanza. Splunkd.log shows no problems reading any of them. My problem is that when I search splunk, I'm missing all data from roughly 100 of the files, files that list monitor shows that I'm watching. I recently added the crcSalt=<SOURCE> line thinking that would help, it has not. Am I missing something obvious?
... View more