All Apps and Add-ons

NFS mount on a Windows Server 2008 R2

oliah
Engager

I created a NFS export to /etc/log on my NetApp then mount this share on the Splunk Windows Server.

[monitor:///N:]

But the filer is not showing up in the dashboard. How can I troubleshoot this?
- Is there any special config to mount the NFS share?
- What are the credentials used to access to the NFS share?

dwaddle
SplunkTrust
SplunkTrust

Some things may be playing a part here.

  1. It doesn't need to be an NFS mount necessarily, you could use CIFS (assuming your filers support CIFS and so on). Splunk just needs access to the /vol/vol0/etc/log on the filer. But, there may be other factors below that affect this negatively.
  2. On my filers, there is a broken symbolic link in /vol/vol0/etc/log that points messages -> /etc/messages. Which is not correct. It should be messages -> ../messages. If I recreate this link properly, Netapp eventually breaks it. (This may play a dual-role in #1 above because I don't know if you mount it via CIFS if the symlinks will work at all)
  3. Maybe [monitor://N:] ? The third slash there is (usually) for a unix absolute path. (But I'm not a Windows person so I may have this wrong)
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...