sorry for noob question, i am using splunk for 2 days...
i am pulling my hair out, cant get it to work....
i have setup an index fschange_test
added this to local/inputs.conf
[fschange:/etc]
index = fschange_test
recurse = true
followLinks = false
signedaudit = false
fullEvent = true
splunk restarted
changed a few files, added some in /etc...
so i go to search type
index="fschange_test"
and get 0 matching events...
the same goes if i add or change some files in splunks /etc dir whitch should work by default...
... View more