Getting Data In

cannot get data from directory path

jsharvina
New Member

i need to index a bunch of xml logs that have an extension of .stats

i was able to just upload one of them from the same network location, and splunk indexed it just fine. but it refuses to index the lot of them form the path. it doesn't come up with any errors, just doesn't add them to the index.

i have tried J:\jobs\2010-06*.stats and J:\jobs\2010-06\

please help.

thanks,

jane

Tags (1)
0 Karma
1 Solution

Lowell
Super Champion

Two thoughts.

1.) Do any of these files contain the exact same information. Or is it possible they that would have the same first/last 256 bytes? If so, you could try adding crcSalt = <SOURCE> in your inputs.conf file. (There are some gotchas to doing this, so I wouldn't recommend trying it unless you suspect this is the case.)

2.) Have you check for any messages regarding this input in your _internal index? Use a search like: index=_internal sourcetype=splunkd ERROR OR WARN

How did you get the first file to load?

View solution in original post

0 Karma

Lowell
Super Champion

Two thoughts.

1.) Do any of these files contain the exact same information. Or is it possible they that would have the same first/last 256 bytes? If so, you could try adding crcSalt = <SOURCE> in your inputs.conf file. (There are some gotchas to doing this, so I wouldn't recommend trying it unless you suspect this is the case.)

2.) Have you check for any messages regarding this input in your _internal index? Use a search like: index=_internal sourcetype=splunkd ERROR OR WARN

How did you get the first file to load?

0 Karma

jsharvina
New Member

mystery solved - it was the fact that the splunk service was running under local user. changing it to a domain account (using the same username and password) made all the logs pile into the index. phew 🙂

0 Karma

jsharvina
New Member

1) the beginning and end characters are not the same for as long as 256 chars

2) searching through internal splunk errors revealed an access is denied error to that directory. i've checked all the permissions though and they're not protected. seems like that's where the issue is though. still remains strange that i was able to import one log from the same location just fine (that was also done through files and directories, but using upload a local file [even though i pointed it to a network location] as opposed to pointing to a path.

still a mystery

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...