Environment has one search head and one search peer. Data is sent to a directory [item (1)] configured to be monitored and indexed by the search peer. Both the search head and search peer have the same "indexes.conf" entry for the index [see item 21)], and the index is showing up in the search head GUI. Search peer has entry in "inputs.conf" to monitor the directory where data is being sent [see item (3)]. When a file is copied into the directory, the expected behavior is for the file to be ingested into Splunk and consequently be searchable; however this behavior is not occurring.
We have other indexes on this environment that do work as intended, but for some reason this particular setup is not working. Any and all help would be appreciated.
Item (1)*
/my/file/dir_ectory
Item (2)
[MY_in_dex]
homePath = $SPLUNK_DB/MY_in_dex
thawedPath = $SPLUNK_DB/thawedpath/MY_in_dex
coldPath = $SPLUNK_DB/coldpath/MY_in_dex
Item (3)
[monitor:///my/FILE/dir_ectory]
index = My_in_dex
*[NOTE: this traversal does start from "/" on a *nix machine]
... View more