Getting Data In

universal forwarder cannot find the path which I want to specify

p1004
New Member

When I install the universal forwarder on my DHCP server, I want to monitor the DHCP folder under system32, but from the software, when I use "path to monitor", I cannot find the DHCP folder through Directory, can you let me know why?

Tags (2)
0 Karma

Runals
Motivator

You using the case sensitive path to your logs? Since you haven't posted the path to your own and you mention system32 I'm guessing the path is the default one. This has worked for me.

[monitor://C:\WINDOWS\system32\dhcp]
sourcetype = DhcpSrvLog
crcSalt = <SOURCE>
disabled = false
whitelist = Dhcp.+\.log

p1004
New Member

Thanks for your answer, I am running a domain admin account, and it is in the local admin group, the permission should not be a problem.

0 Karma

ShaneNewman
Motivator

Is Splunk setup to run as a system account or a domain account? If it is setup as a domain account, it may not have the correct permissions to that directory.

0 Karma

ShaneNewman
Motivator

If you browse the folder directory as the domain account on the server itself, can you see the files you want to monitor?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...