Hey,
I tried to index a .csv file several times and I can see the file in
"Manager » Data inputs » Files & directories" but I can't find it?!?!
I tried a different file and directory and there was the same result...
I can also see all indexes due to the settings of "Access controls » Roles".
To make a long story short I have no idea why i can't find the files that are indexed....
Hi Jochen
is your input index into another then the default index?
if so, do you search the correct index?
what does splunkd.log report?
have you searched index=_internal for the file in question?
cheers,
MuS
same problem here. I've put it in default, main, created my own new index, given it default sourcetypes and custom sourcetypes and it just doesn't appear anywhere.
Never indexed, never uploaded, as far as I can tell. What gives?
Hi Jochen
is your input index into another then the default index?
if so, do you search the correct index?
what does splunkd.log report?
have you searched index=_internal for the file in question?
cheers,
MuS
ok, now I now why it doesn't work, but how do i get the data back in splunk:-)?
That could very well be the problem. Splunk keeps track of how far into the file it has read. If you delete the file and reupload it, it will not be reindexed. Some more information is available here: http://docs.splunk.com/Documentation/Splunk/latest/Data/Howlogfilerotationishandled
okay, splunk will not index this file again in this case.
just make sure there is no permission problem and the path is accessible for splunk, then it should be fine. do you use any regex for this input and props/transforms as well?
could you post the stanza from inputs.conf?
no result... the thing is I already indexed the file a few days ago but then deleted it... could that be the problem? and if i want to upload a file that's fine, i just got problems if i want to monitor a file/directory...
Having a very similar problem on my side, May i know what you did to resolve this.
@ryantzj, see this answer http://answers.splunk.com/answers/27230/what-is-the-best-method-to-reindex-the-file-after-deleting-t...
it could also be a permission problem, meaning the user splunk is running is not allowed to read the file.
try searching for the file name in index=_internal instead of path name.
Hi,
Input index is default index... Splunkd.log reports "TailingProcessor - Parsing configuration stanza: monitor:C:..." and I searched index=_internal and then the path of the file but there were no results..