Dashboards & Visualizations

file modified during boot not indexed

wieljer
Engager

Hi Everyone,

I have a problem with Splunk not indexing an XML file, modified during the windows boot process. Windows 10 creates an encrypted file during bootup which our powershell script parses and places the result in a location "c:\tpm" using a windows startup script.

What I've tried
- I added MAX_EVENTS to the props.conf and also on the sourcetype on the indexer for 100,000 lines because it is larger than the default limit.
- If I open the xml file manually and add something into it, Splunk will pickup those changes.

Since the file is not indexed without being modified while the SUF is running, I figured a setting might be needed. Any ideas?

Thanks,
wieljer

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What are the current inputs.conf settings for the file?

---
If this reply helps you, Karma would be appreciated.
0 Karma

wieljer
Engager

Hey thanks for the inquiry
[monitor://C:\TPM]
disabled = false
followTail = 0
sourcetype = winTPM
index = win10

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...