Getting Data In

new monitor stanza not indexed

ktang
Explorer

Hello,

On my Windows box, I've added a new monitor stanza in my local inputs.conf file. The config is:

[monitor://<local_dir_path>]
index = rsop

I'm not seeing the directory being monitored. It doesn't look like the data is being fed. Nor do I see any events in my splunkd.log file indicating the monitor path or index. The splunkd logon account has full control to the directory.

Am I missing something? How else can I troubleshoot my issue?

Thanks,
ktang

0 Karma
1 Solution

ktang
Explorer

Yes, the index name is defined in the indexer.

I think I've resolved my issue by adding crcSalt = attribute to the monitor stanza. Didn't realize I had to do this until reading up on how Splunk prevents itself from redundant indexing.

I'm now able to index my monitored dir. Would anyone care to comment about doing it another way?

Thanks.

View solution in original post

ktang
Explorer

Yes, the index name is defined in the indexer.

I think I've resolved my issue by adding crcSalt = attribute to the monitor stanza. Didn't realize I had to do this until reading up on how Splunk prevents itself from redundant indexing.

I'm now able to index my monitored dir. Would anyone care to comment about doing it another way?

Thanks.

gkanapathy
Splunk Employee
Splunk Employee

Have you defined and created an index with that name on the indexer? If not, the events will be discarded.

0 Karma

ktang
Explorer

I would like to leave this question open for another day to hear from you Splunk experts. I'll mark the post as answered 10/21.

Thanks all.

0 Karma

ktang
Explorer

Thanks for the reply Ayn.
Yes, I restarted splunkd after making the conf changes.
I ran the cmd and did see that my monitor stanza was listed.

I just checked to see if it had indexed yet but still 0 results. ..?

I appreciate your help.

0 Karma

Ayn
Legend

Sorry it's hard to troubleshoot remotely. A good idea would be to run amrit's excellent script that shows the status of each input. http://blogs.splunk.com/2011/01/02/did-i-miss-christmas-2/

This script should really be included with Splunk from the start.

0 Karma

Ayn
Legend

Did you restart Splunk?

To see what inputs Splunk "sees", do: $SPLUNK_HOME\bin\splunk cmd btool inputs list

If you don't see your input there, that's a start - if Splunk doesn't see it, it obviously won't index anything either.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...