Getting Data In

To monitor a Folder in Windows Server ?

chimbudp
Contributor

I need to monitor the Assembly folder in Windows Server :
[monitor://C:\Windows\assembly]
index=Assembly_monitor

the above stanza forwards no data into Splunk indexer.

i have set the source type as assembly and modified as below inputs.conf:

[monitor://C:\Windows\assembly]
index=Assembly_monitor
sourcetype=Assembly

& also edited props.conf as :

[Assembly]
NO_BINARY_CHECK = true

-- Even also i am not getting any data 😞
Please help

Tags (2)
0 Karma

arvidn
New Member

Hi, I think you are missing "\" before Windowsassembly

[monitor://C:\Windowsassembly]

0 Karma

chimbudp
Contributor

Yes. it was not displayed in question & ur answer too.
But i am using backslash wherever it required

0 Karma

arvidn
New Member

Should be "backslash" in front of Windowsassembly. But not shown in my answere, probably missing in question too?

0 Karma

Ayn
Legend
  • Do you see other data from this forwarder in your indexer?
  • Have you checked splunkd.log on the forwarder?
  • Did you have a look at the status of file inputs (http://blogs.splunk.com/2011/01/02/did-i-miss-christmas-2/)?
  • Most of all, why would you want to index the binary data in the assembly directory? What are you trying to achieve?
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...