<?xml version="1.0" ?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
	<channel>
		<title>Splunk Base : SplunkAdministration : #3560</title>
		<link>http://www.splunk.com/support/forum:SplunkAdministration/3560</link>
		<description></description>
		<pubDate>Mon, 13 Feb 2012 19:13:08 PST</pubDate>
		<lastBuildDate>Mon, 13 Feb 2012 19:13:08 PST</lastBuildDate>
		<language>en-us</language>
		<copyright>http://creativecommons.org/licenses/by-nc-nd/2.5/</copyright>
		<item>
			<title>Unable to index files</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3560/11556</link>
			<description>&lt;p&gt;I see these are only readable by root and the root group, so splunk does have to run as root. You can run &amp;quot;./splunk list monitor&amp;quot; on the command line to see if they are being monitored.&lt;/p&gt;

&lt;p&gt;Oh, and finally, have you enabled the Unix app? If so, it's sending your logs into a non-default index, which you could see by querying &amp;quot;index=*&amp;quot;. I thought they had stopped doing that to the /var/log files, but I see in my 4.0.5 that it's still doing that.&lt;/p&gt;

</description>
			<pubDate>Thu, 12 Nov 2009 21:52:30 PST</pubDate>
			<author>gkanapathy</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3560/11556</guid>
		</item>
		<item>
			<title>Unable to index files</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3560/11532</link>
			<description>&lt;p&gt;i am running Splunk 4.0.6 with a demo enterprise license and am having problems adding several syslog generated files into splunk.&lt;/p&gt;

&lt;p&gt;I use syslog to store remote syslog streams from routers on our network.&lt;/p&gt;

&lt;p&gt;I am trying to monitor all of these files:&lt;br /&gt;
-rw-r----- 1 root root    2522 2009-11-12 07:53 network-comwaves-cm-rtr-200911.log&lt;br /&gt;
-rw-r----- 1 root root  198699 2009-11-12 10:53 network-comwaves-i35-rtr-200911.log&lt;br /&gt;
-rw-r----- 1 root root     178 2009-11-11 01:33 network-volznet-140th-rtr-200911.log&lt;br /&gt;
-rw-r----- 1 root root    2972 2009-11-12 08:58 network-volznet-lh-rtr-200911.log&lt;br /&gt;
-rw-r----- 1 root root  489128 2009-11-12 10:53 &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/VolzFirewall&quot;&gt;VolzFirewall&lt;/a&gt;-200911.log&lt;br /&gt;
xeon1:/var/log/network #&lt;/p&gt;

&lt;p&gt;I have created all of the data input files entries in the web interface:&lt;br /&gt;
  Full path on server           Set host           Source type           Index           Number of files           App           Enabled         Actions&lt;br /&gt;
/var/log/network/network-comwaves-cm-rtr-*     Constant Value     Automatic     default         search     &lt;br /&gt;
| Disable     Clone | Delete&lt;br /&gt;
/var/log/network/network-comwaves-i35-rtr-*     Constant Value     Automatic     default         search     &lt;br /&gt;
| Disable     Clone | Delete&lt;br /&gt;
/var/log/network/network-volznet-140th-rtr-*     Constant Value     Automatic     default         search     &lt;br /&gt;
| Disable     Clone | Delete&lt;br /&gt;
/var/log/network/network\-comwaves\-i35\-rtr\-*     Constant Value     Automatic     default         search     &lt;br /&gt;
| Disable     Clone | Delete&lt;br /&gt;
$SPLUNK_HOME/etc/apps/sample_app/logs     Constant Value     sendmail     sample     2     sample_app     &lt;br /&gt;
| Disable     Clone&lt;br /&gt;
$SPLUNK_HOME/var/log/splunk     Constant Value     Automatic     _internal     18     system     &lt;br /&gt;
| Disable     Clone&lt;br /&gt;
/var/log/mail     Constant Value     Automatic     default         search     &lt;br /&gt;
| Disable     Clone | Delete&lt;br /&gt;
/var/log/messages     Constant Value     Automatic     default         search     &lt;br /&gt;
| Disable     Clone | Delete&lt;br /&gt;
/var/log/network/network-volznet-lh-rtr-*     Constant Value     Automatic     default         search     &lt;br /&gt;
| Disable     Clone | Delete&lt;br /&gt;
/var/log/network/&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/VolzFirewall&quot;&gt;VolzFirewall&lt;/a&gt;-*     Constant Value     Automatic     default     1     search     &lt;br /&gt;
| Disable     Clone | Delete&lt;/p&gt;

&lt;p&gt;However only the syslog messages, mail and Volzfirewall entries are working.  I have tried on one entry &amp;quot;i35-rtr&amp;quot; to use \- thinking the &amp;quot;-&amp;quot; might be a special character that needs to be escaped, but that did not help either.&lt;/p&gt;

&lt;p&gt;Any directions to see what I'm doing wrong as to why these files aren't being indexed?&lt;/p&gt;

</description>
			<pubDate>Thu, 12 Nov 2009 09:03:58 PST</pubDate>
			<author>TheCowStir</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3560/11532</guid>
		</item>
	</channel>
</rss>

