I am trying to extract some information from a text file. This is how my inputs.conf looks like,
[monitor://C:\Temp\ServerInfo_Tag.txt]
sourcetype = ABC
index = filelog
crcSalt =
I pushed this config across 4000 windows servers. Ideally Splunk should pickup the file content as soon as the config is pushed.
But strange thing here is, I can see the file content as an event on Splunk for ONLY 3000 servers.
For the other 1000 servers I have to modify the file to get the file content on Splunk.
Is there a way to get the file content without modifying the file?
Config doesn't seem to be an issue here as it it working for other servers and there are no port related issues on the other 1000 servers as I can see the data on Splunk after modifying the file.
Any suggestions here are highly appreciated.
Thanks,
Channesh
... View more