Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Monitoring a directory, why is Splunk not indexing a new file that has the same name as a previously indexed file?

$
0
0
SPLUNK is monitoring a directory with below configuration in inputs.conf: [monitor:///*/*/*] sourcetype=exampleA_sourcetype index=exampleA_index blacklist = \.(gz|zip)$ ignoreOlderThan = 1d initCrcLength = 750 We had a file in the directory "example_readafile.log" in the directory on 31st August and Splunk monitored it correctly. On 1st September, we dropped a new file with same name (example_readafile.log) that had different content in it, but it was not monitored by SPLUNK. Can anyone please explain this behavior?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>