Refine your search:

We have a text file DEFAULT.PFL(which has just 3 lines of text) in all the below paths /usr/sap/IX4/SYS/profile /usr/sap/IXV/SYS/profile /usr/sap/IXD/SYS/profile /usr/sap/IXT/SYS/profile And I am using

[monitor:///usr/sap/IX4/SYS/profile] disabled = false sourcetype = IX4webdisp_profile index = erp_webdisp crcSalt = IX4webdisp_profile

Similarly I have created monitors for other file paths. Splunk is reading all other files except the DEFAULT.PFL in all the above file paths.

I tried to create seperate monitor [monitor:///usr/sap/IX4/SYS/profile/DEFAULT.PFL] but still splunk does not read this file. All file permissions are same. Please let me know how to read this file..

asked 23 Nov '11, 01:42

sushildabare's gravatar image

sushildabare
1129
accept rate: 0%

edited 23 Nov '11, 01:44


One Answer:

You should get amrit's script that shows the status of all configured inputs. It should give you some information that you can use for troubleshooting. It's available here: http://blogs.splunk.com/2011/01/02/did-i-miss-christmas-2/

link

answered 23 Nov '11, 02:07

Ayn's gravatar image

Ayn
24.9k3717
accept rate: 41%

Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×137
×1

Asked: 23 Nov '11, 01:42

Seen: 1,069 times

Last updated: 23 Nov '11, 02:07

Copyright © 2005-2012 Splunk Inc. All rights reserved.