Getting Data In

How to configure universal forwarder or use environment variables to monitor folder in different Windows OS versions?

steveo69
Explorer

Using the Universal Forwarder I need to monitor a folder, so I am editing the inputs.conf file.

However, in Windows XP / Windows 2003 the folder is located in :

C:\Documents and Settings\All Users

In Windows 7 and later it is located in C:\ProgramData

I have tried to use the Windows environment variable %AllUsersProfile% but in the splunkd log filer I get an error:

TailingProcessor - Parsing configuration stanza: monitor://%allusersprofile%\Application Data\myfolder.
TailingProcessor - Input stanza path, '%allusersprofile%\Application Data\myfolder\' is not absolute. This is a configuration error and may not work / break things. Change this path to an absolute path.

So how can I use an environment variable or change the config so that it works on bother older and newer Windows OS?

Thanks

1 Solution

strive
Influencer

Good to know that it worked. Dont forget to cast your vote 🙂

0 Karma

steveo69
Explorer

Thanks for the link strive - thats exactly what I needed.

One thing which fooled me - not being a programmer of any type or background - was that the environment variable I wanted to use I understood to be %variable% - however in the conf file it seems you need to use the format $variable

0 Karma

steveo69
Explorer

The forum has removed all the back slashes from my post....

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...