Data is being indexed if i use the option "Index a file once from this Splunk server"
But not indexed if i use "Continuously index data from a file or directory this Splunk instance can access" option . Please help.
Try adding it in inputs.conf file.
[monitor:///location/to/log/file/folder]
index = test1
sourcetype = log4j
disabled = false
Thank you so much it helped me a lot. It was asking fro crcSalt
See status of file input here.
https://YOURHOST:8089/admin/services/inputstatus/TailingProcessor:FileStatus
Try adding it in inputs.conf file.
[monitor:///location/to/log/file/folder]
index = test1
sourcetype = log4j
disabled = false
Thank you so much . it was crcSalt issue
Back slashes if your using on windows platform..