Splunk Enterprise

Splunk cannot index $SPLUNK_HOME/var/log

daniel_splunk
Splunk Employee
Splunk Employee

When I search index=_internal, log from $SPLUNK_HOME/var/log cannot be indexed. I check splunkd.log and found out the inputs.conf is disabled.

Any idea what casuse this.

01-27-2015 14:38:11.494 +1030 INFO  TailingProcessor - TailWatcher initializing...
01-27-2015 14:38:11.494 +1030 INFO  TailingProcessor - Input module disabled in inputs.conf, will not load.
Tags (1)
0 Karma
1 Solution

daniel_splunk
Splunk Employee
Splunk Employee

One possible reason is the default stanza is disabled.

Run below command to verify.

./splunk cmd btool --debug inputs list default

If the return got a line saying 'disabled = 1', that is the culript.

View solution in original post

0 Karma

daniel_splunk
Splunk Employee
Splunk Employee

One possible reason is the default stanza is disabled.

Run below command to verify.

./splunk cmd btool --debug inputs list default

If the return got a line saying 'disabled = 1', that is the culript.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...