Getting Data In

"Continuously index data from a file or directory this Splunk instance can access"

Rukmani_Splunk
Path Finder

Data is being indexed if i use the option "Index a file once from this Splunk server"
But not indexed if i use "Continuously index data from a file or directory this Splunk instance can access" option . Please help.

Tags (1)
0 Karma
1 Solution

krish3
Contributor

Try adding it in inputs.conf file.

[monitor:///location/to/log/file/folder]
index = test1
sourcetype = log4j
disabled = false

View solution in original post

0 Karma

Rukmani_Splunk
Path Finder

Thank you so much it helped me a lot. It was asking fro crcSalt

0 Karma

somesoni2
Revered Legend
0 Karma

krish3
Contributor

Try adding it in inputs.conf file.

[monitor:///location/to/log/file/folder]
index = test1
sourcetype = log4j
disabled = false
0 Karma

Rukmani_Splunk
Path Finder

Thank you so much . it was crcSalt issue

0 Karma

krish3
Contributor

Back slashes if your using on windows platform..

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...