Hey Luke. Thanks again for your continued follow-up.
In my case, the account under which the splunk service is running on the indexer is a domain admin. So no permissions issues. Verified that as that account I could access the file.
The Splunk forum is removing your backslashes, so a little hard to see your example. I reverted back to my original pathing, which is a typical UNC path (two leading backslashes, a single backslash between directories).
The file_meta_data_modular_input.log has the following errors:
2015-11-17 13:51:13,760 ERROR Execution failed
Traceback (most recent call last):
File "D:\Program Files\Splunk\etc\apps\file_meta_data\bin\file_info_app\modular_input.py", line 1320, in execute
self.do_run(in_stream, log_exception_and_continue=True)
File "D:\Program Files\Splunk\etc\apps\file_meta_data\bin\file_info_app\modular_input.py", line 1220, in do_run
input_config)
File "D:\Program Files\Splunk\etc\apps\file_meta_data\bin\file_meta_data.py", line 350, in run
results, new_latest_time = [self.get_file_data(file_path, logger=self.logger, latest_time=latest_time, must_be_later_than=must_be_later_than, file_hash_limit=file_hash_limit)]
ValueError: need more than 1 value to unpack
... View more