my inputs.conf file updated with below content
[monitor:/$SPLUNK_HOME/splunk_monitor]
index =
sourcetype =
this is not indexing any files, I cant see any events in search ..
I tried searching with sourcetype, index, source etc...with many combinations.. still no result
I tried checking few log files splunkd.log etc..
Please guide me how can I trouble shoot
Thank you
Amarander Busireddy
Hi Amarander,
Please try adding a monitor input using CLI, for example:
./splunk add monitor /var/log/ -index newindex
For details, please refer to documentation: http://docs.splunk.com/Documentation/Splunk/6.5.1/Data/MonitorfilesanddirectoriesusingtheCLI
Hope this helps. Thanks!
Hunter
We can start with I can't find my data!
Hi Amarander,
Please try adding a monitor input using CLI, for example:
./splunk add monitor /var/log/ -index newindex
For details, please refer to documentation: http://docs.splunk.com/Documentation/Splunk/6.5.1/Data/MonitorfilesanddirectoriesusingtheCLI
Hope this helps. Thanks!
Hunter