Getting Data In

How do I Monitor a UNC path?

seanlon11
Path Finder

From server1, I have access to the desired UNC path, and this same user is running splunk, so I know access is not an issue.

\etc\apps\search\local\inputs.conf

[monitor://\\SANCIFS_TDC_NETAPP01A.SAN.MyCompany.Com\CIFS_COGNOS$\Test\Logs]
disabled = false
host = sancifs_test
index = default
sourcetype = motio_test

I have tried many different permutations of the forward and back slash for my monitor stanza, but nothing has worked so far.

What am I doing wrong?

Thanks, Sean

Tags (1)
1 Solution

seanlon11
Path Finder

dang, that is going to make me mad. I set the Service to run as a different user, and it now works. (figuring out the syntax of how to get Windows to recognize the user was quite a chore)

View solution in original post

0 Karma

seanlon11
Path Finder

dang, that is going to make me mad. I set the Service to run as a different user, and it now works. (figuring out the syntax of how to get Windows to recognize the user was quite a chore)

0 Karma

Paolo_Prigione
Builder

Is the indexer (or forwarder) a linux or window box?
If windows, might it be that the "local system account" under which splunk runs by default has no access to that folder?
Uhm, is that a dollar sign after COGNOS? Is it supported in paths?

0 Karma

seanlon11
Path Finder

1) Yes, I have restarted Splunk after updating the inputs.conf

2) Splunk 4.1.1 (build 78281)

3) 14 files

0 Karma

Genti
Splunk Employee
Splunk Employee

few standard questions: 1- Have you restarted splunk after changing the config file? 2 - what version of splunk are you using? how many files are in the Logs directory?

0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...