All,
I've looked at a couple prior articles regarding this but can't seem to find any solutions on the Windows side. There is this; http://answers.splunk.com/answers/8857/directory-size-question
However this relies on a script on the local machine creating a log file for Splunk to consume.
Is there a way to do this with the forwarder, or through some other mechanism like a native windows log?
To skip the script's logfile you can have Splunk call one directly as a scripted input on your forwarders. Everything printed to stdout will be forwarded to your indexers.
Could you possibly elaborate? I understand the concept, but could you point me towards an example or documentation?