Splunk Search

Monitor a file or directory indexing no longer working

hoffmandirt
Explorer

The "monitor a file or directory" data input option is no longer working. When I add a new file this way, the source nor the source type show up in the Search application. I can't run any queries against the sources. What would be causing this? My free trial license recently expired, but I don't think that's the issue. I am using Splunk v4.1.5.


I found this in the $SPLUNK_HOME\etc\system\default\indexes.conf file:

[main]
homePath   = $SPLUNK_DB\defaultdb\db
coldPath   = $SPLUNK_DB\defaultdb\colddb
thawedPath = $SPLUNK_DB\defaultdb\thaweddb
maxMemMB = 20
maxConcurrentOptimizes = 6
maxHotIdleSecs = 86400
maxHotBuckets = 10
maxDataSize = auto_high_volume

Whats the maxMemMB property? That index is currently 22mb in size. Also I created a new index and the monitor file option worked as expected. Thoughts?

Tags (2)
0 Karma

Simeon
Splunk Employee
Splunk Employee

Unless you convert to the free version of Splunk, you may be experiencing searches getting disabled. You should check your license status (in the manager portion of the UI) to see the status of your license. Also, it might be possible you are sending data to an index that is not shown in the summary page by default.

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...