Getting Data In

Accessing SharePoint directories using UNC: Why splunkd.log shows "Monitoring file or directory that doesn't exist at startup time"?

DonDandrea
Path Finder

I am trying to use fschange to monitor some SharePoint directories. As a user on my remote forwarder box I can access the directories. I am logged onto the server using the same domain account that splunkd uses. When I enable the fschange monitoring I get the following message in the splunkd.log.

08-08-2014 09:17:41.259 -0400 WARN FSChangeMonitor - Monitoring file or directory that doesn't exist at startup time

any help you could provide would be greatly appreciated.

Thank you
Don

Tags (3)
0 Karma
1 Solution

DonDandrea
Path Finder

We never found a solution to this problem. The data is stored in a SQL database. You can access the data using a UNC path from a windows workstation or server but SharePoint is rendering the output. Splunk does not access the data in the same way and SharePoint is not rendering the data for Splunk. We considered going after the data directly from the DB but Microsoft discourages that. In the end our solution will be to send the data someplace other than SharePoint.

View solution in original post

0 Karma

DonDandrea
Path Finder

We never found a solution to this problem. The data is stored in a SQL database. You can access the data using a UNC path from a windows workstation or server but SharePoint is rendering the output. Splunk does not access the data in the same way and SharePoint is not rendering the data for Splunk. We considered going after the data directly from the DB but Microsoft discourages that. In the end our solution will be to send the data someplace other than SharePoint.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...