Hi
I want to monitor multiple csv files in a folder name Fwd Test on E drive. I have added below code to my inputs.conf file but Splunk is not picking up data. Do i need to make any changes in props.conf as well?
[monitor://E:\Fwd Test]
index=dir_test
sourcetype=csv
"Splunk is not picking up data." do you mean that the first version of the file was indexed, but not the next ones ?
search in the _internal splunkd.log for the file name, they may be skipped because considered as duplicates.
Please double check that your new files do not have identical header than the previous one.
and read this documents with care : http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/HowLogFileRotationIsHandled
I think the data is now picked from the files but, when we update the existing csv files splunk doesn't take only the updated rows it take the whole CSV content again.. This can be reproduced easily.
If your application is adding rows to the file by adding bytes to the end, then it is behaving like a logfile, and splunk will handle that.
if your application is adding rows to the file by rewriting the entire file, and the bytes are different, then it is not behaving like a logfile, and splunk is not designed to handle that.
Did you restart Splunk after updating the inputs config?
This question is unclear. You say that Splunk is not picking up data. Then you say that splunk is duplicating the data.
These two statements seem to be in conflict. Can you clarify?