Getting Data In

fschange with universal Forwarder

SplunkUser5888
Path Finder

Hey guys, I've seen a couple of similar questions to mine but nothing has helped. I have a very simple edit in the inputs.conf of my Universal Forwarder on a Windows Server.
It has in it;

[default]
host = server2003-splu
[fschange:C:\Program Files\]
index = _audit
signedaudit = false
#pollPeriod = 1
#hashMaxSize = 10485760
#fullEvent = true

[script://$SPLUNK_HOME\bin\scripts\splunk-perfmon.path]
disabled = 0

Any reason why when i do a search

index=_audit sourcetype=fs_notification host=server2003-splu

it doesn't come back with anything even after adding, changing and deleting files and folders in the Program Files directory?

Thanks for any help you can give me

0 Karma
1 Solution

SplunkUser5888
Path Finder

It works now. Same config, same search nothing changed. It was a stupid mistake after all, the Universal Forwarder was not being restarted properly.

Answer:

Make sure you restart the server properly

C:\Program Files\SplunkUniversalForwarder\bin>splunk.exe restart

View solution in original post

0 Karma

SplunkUser5888
Path Finder

It works now. Same config, same search nothing changed. It was a stupid mistake after all, the Universal Forwarder was not being restarted properly.

Answer:

Make sure you restart the server properly

C:\Program Files\SplunkUniversalForwarder\bin>splunk.exe restart
0 Karma

SplunkUser5888
Path Finder

sorry, I didn't mean to sound pushy

0 Karma

Ayn
Legend

Your question was posted only an hour ago. You can't expect people doing this on their spare time to always see and respond to the question immediately...

Ayn
Legend

The sourcetype should be fs_notification, not fs_notifications. Also you have a typo in the stanza below (diasbled instead of disabled), though that shouldn't affect the fschange stanza.

0 Karma

SplunkUser5888
Path Finder

Hey, thanks for your answer, but that's a typo on my behalf, any query I use to search does not bring any results (I'll edit the question with the right search parameters though thanks for pointing it out)

0 Karma

SplunkUser5888
Path Finder

No one knows how I can change my file to make it work? I don't mind rewriting it if someone thinks it needs to be changed completely

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...