<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After installing the File/Directory Information Input add-on, why are no logs being indexed? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-installing-the-File-Directory-Information-Input-add-on-why/m-p/251832#M28878</link>
    <description>&lt;P&gt;Using latest version I'm still having issues.  Only seeing occasional logging to the correctly configured index on restarting the service.  The interval is being ignored here.&lt;/P&gt;

&lt;P&gt;Looking at internal logs:&lt;BR /&gt;
Index=_internal source="C:\Program Files\Splunk\var\log\splunk\file_meta_data_modular_input.log"&lt;/P&gt;

&lt;P&gt;Seeing events like:&lt;/P&gt;

&lt;P&gt;INFO Completed retrieval of file data....&lt;BR /&gt;
WARNING Unable to get the ACL data, reason=(5, 'GetFileSecurity', 'Access is denied.')...&lt;BR /&gt;
INFO Time is later than filter, st_mtime=1322859631.165719, must_be_later_than=None, path='...&lt;BR /&gt;
INFO Time is later than filter, st_ctime=1330974351.030764, must_be_later_than=None, path=...&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 14:13:49 GMT</pubDate>
    <dc:creator>smudge797</dc:creator>
    <dc:date>2020-09-29T14:13:49Z</dc:date>
    <item>
      <title>After installing the File/Directory Information Input add-on, why are no logs being indexed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-installing-the-File-Directory-Information-Input-add-on-why/m-p/251825#M28871</link>
      <description>&lt;P&gt;After installing File/Directory Information Input add-on on Splunk 6.5.1 for Windows and configuring to UNC path, I see the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;INFO Time is later than filter, st_mtime=1459251861.8578942, must_be_later_than=None
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 24 Jan 2017 17:03:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-installing-the-File-Directory-Information-Input-add-on-why/m-p/251825#M28871</guid>
      <dc:creator>smudge797</dc:creator>
      <dc:date>2017-01-24T17:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: After installing the File/Directory Information Input add-on, why are no logs being indexed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-installing-the-File-Directory-Information-Input-add-on-why/m-p/251826#M28872</link>
      <description>&lt;P&gt;@smudge797 - Please provide more information and context as to what you need help with as it is not clear. Generally, the more information you provide, the better chance of  being answered by experts in the Answers community. Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2017 17:17:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-installing-the-File-Directory-Information-Input-add-on-why/m-p/251826#M28872</guid>
      <dc:creator>aaraneta_splunk</dc:creator>
      <dc:date>2017-01-24T17:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: After installing the File/Directory Information Input add-on, why are no logs being indexed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-installing-the-File-Directory-Information-Input-add-on-why/m-p/251827#M28873</link>
      <description>&lt;P&gt;Make sure that NTP is set on both your forwarder (the Windows machine) and the Indexers.  Things cannot happen in the future.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2017 19:06:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-installing-the-File-Directory-Information-Input-add-on-why/m-p/251827#M28873</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-01-24T19:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: After installing the File/Directory Information Input add-on, why are no logs being indexed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-installing-the-File-Directory-Information-Input-add-on-why/m-p/251828#M28874</link>
      <description>&lt;P&gt;This is the app: &lt;A href="https://splunkbase.splunk.com/app/2776/" target="_blank"&gt;https://splunkbase.splunk.com/app/2776/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;This is the configured input:&lt;/P&gt;

&lt;P&gt;[file_meta_data://ACETestFolder]&lt;BR /&gt;
file_hash_limit = 500MB&lt;BR /&gt;
file_path = \\acetest&lt;BR /&gt;
include_file_hash = 0&lt;BR /&gt;
interval = 15m&lt;BR /&gt;
only_if_changed = 1&lt;BR /&gt;
recurse = 1&lt;/P&gt;

&lt;P&gt;There is an initial pull of events seen in the main index, some 3k events&lt;BR /&gt;
similar to this:&lt;BR /&gt;
time="Tue Jan 24 16:37:39 2017" is_directory=1 file_count=0 directory_count=16 path=\\acetest atime="Thu Dec 22 12:52:26 2016" atime_epoch=1482429146.82 ctime="Thu Oct 15 16:15:49 2015" ctime_epoch=1444940149.33 dev=0 gid=0 ino=0 mode=16895 mtime="Thu Dec 22 12:52:26 2016" mtime_epoch=1482429146.82 nlink=0 size=4096 uid=0 owner=Administrators\BUILTIN owner...(lots more fields)&lt;/P&gt;

&lt;P&gt;All events have same timestamp time="Tue Jan 24 16:37:39 2017" which is correctly indexed in main.&lt;/P&gt;

&lt;P&gt;In the index= _internal source="C:\Program Files\Splunk\var\log\splunk\file_meta_data_modular_input.log"&lt;BR /&gt;
Events like:&lt;BR /&gt;
2017-01-24 16:37:34,867 INFO Time is later than filter, st_mtime=1482429146.8163483, must_be_later_than=0, path='\\\acetest'&lt;/P&gt;

&lt;P&gt;Have second input:&lt;/P&gt;

&lt;P&gt;[file_meta_data://fileTest]&lt;BR /&gt;
file_hash_limit = 500MB&lt;BR /&gt;
file_path = \\someshare_archive06$&lt;BR /&gt;
include_file_hash = 0&lt;BR /&gt;
interval = 15m&lt;BR /&gt;
only_if_changed = 1&lt;BR /&gt;
recurse = 1&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;No events in main.&lt;/P&gt;

&lt;P&gt;index=_internal source="C:\Program Files\Splunk\var\log\splunk\file_meta_data_modular_input.log"&lt;/P&gt;

&lt;P&gt;2017-01-24 17:35:24,240 INFO Time is later than filter, st_mtime=1333460403.592, must_be_later_than=0, path="\\\someshare_archive06$\~filedetails.xlsm3.xlsm"&lt;/P&gt;

&lt;P&gt;Also lost of these:&lt;/P&gt;

&lt;P&gt;2017-01-24 17:29:38,009 ERROR Error when processing path="blah", reason="(1332, 'LookupAccountSid', 'No mapping between account names and security IDs was done.')" Traceback (most recent call last): File "C:\Program Files\Splunk\etc\apps\file_meta_data\bin\file_meta_data.py", line 381, in get_file_data windows_acl_info = cls.get_windows_acl_data(file_path, logger) File "C:\Program Files\Splunk\etc\apps\file_meta_data\bin\file_meta_data.py", line 254, in get_windows_acl_data sid_resolved = win32security.LookupAccountSid(None, sid) error: (1332, 'LookupAccountSid', 'No mapping between account names and security IDs was done.')&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:32:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-installing-the-File-Directory-Information-Input-add-on-why/m-p/251828#M28874</guid>
      <dc:creator>smudge797</dc:creator>
      <dc:date>2020-09-29T12:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: After installing the File/Directory Information Input add-on, why are no logs being indexed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-installing-the-File-Directory-Information-Input-add-on-why/m-p/251829#M28875</link>
      <description>&lt;P&gt;NTP is working.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 15:34:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-installing-the-File-Directory-Information-Input-add-on-why/m-p/251829#M28875</guid>
      <dc:creator>smudge797</dc:creator>
      <dc:date>2017-01-26T15:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: After installing the File/Directory Information Input add-on, why are no logs being indexed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-installing-the-File-Directory-Information-Input-add-on-why/m-p/251830#M28876</link>
      <description>&lt;P&gt;The only thing I can think of is that something in your environment isn't allowing the account SID to be looked up.&lt;/P&gt;

&lt;P&gt;I'm going to make input succeed even if the SID lookup fails.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2017 04:54:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-installing-the-File-Directory-Information-Input-add-on-why/m-p/251830#M28876</guid>
      <dc:creator>LukeMurphey</dc:creator>
      <dc:date>2017-03-17T04:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: After installing the File/Directory Information Input add-on, why are no logs being indexed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-installing-the-File-Directory-Information-Input-add-on-why/m-p/251831#M28877</link>
      <description>&lt;P&gt;This happens when there is no mapping between the account names and the SIDs available on the host. See &lt;A href="http://www.rebeladmin.com/2016/01/how-to-fix-error-no-mapping-between-account-names-and-security-ids-in-active-directory/"&gt;http://www.rebeladmin.com/2016/01/how-to-fix-error-no-mapping-between-account-names-and-security-ids-in-active-directory/&lt;/A&gt; for information.&lt;/P&gt;

&lt;P&gt;I am going to modify the input so that it proceeds even if SID lookup fails. This will done under &lt;A href="https://lukemurphey.net/issues/1789"&gt;this ticket&lt;/A&gt; and will be released in version 1.1.1.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Update&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;I just released version 1.1.1 which should allow the input to work even if the SID and account name mapping doesn't exist on the host. You won't get the Windows ACL data if this condition exists, but the input will still run.&lt;/P&gt;

&lt;P&gt;Please let me know if that fixes the problem (or just accept this answer).&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2017 05:05:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-installing-the-File-Directory-Information-Input-add-on-why/m-p/251831#M28877</guid>
      <dc:creator>LukeMurphey</dc:creator>
      <dc:date>2017-03-17T05:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: After installing the File/Directory Information Input add-on, why are no logs being indexed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-installing-the-File-Directory-Information-Input-add-on-why/m-p/251832#M28878</link>
      <description>&lt;P&gt;Using latest version I'm still having issues.  Only seeing occasional logging to the correctly configured index on restarting the service.  The interval is being ignored here.&lt;/P&gt;

&lt;P&gt;Looking at internal logs:&lt;BR /&gt;
Index=_internal source="C:\Program Files\Splunk\var\log\splunk\file_meta_data_modular_input.log"&lt;/P&gt;

&lt;P&gt;Seeing events like:&lt;/P&gt;

&lt;P&gt;INFO Completed retrieval of file data....&lt;BR /&gt;
WARNING Unable to get the ACL data, reason=(5, 'GetFileSecurity', 'Access is denied.')...&lt;BR /&gt;
INFO Time is later than filter, st_mtime=1322859631.165719, must_be_later_than=None, path='...&lt;BR /&gt;
INFO Time is later than filter, st_ctime=1330974351.030764, must_be_later_than=None, path=...&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:13:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-installing-the-File-Directory-Information-Input-add-on-why/m-p/251832#M28878</guid>
      <dc:creator>smudge797</dc:creator>
      <dc:date>2020-09-29T14:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: After installing the File/Directory Information Input add-on, why are no logs being indexed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-installing-the-File-Directory-Information-Input-add-on-why/m-p/251833#M28879</link>
      <description>&lt;P&gt;A few things to look into:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Do the "Time is later than filter" logs include the files that you want logs for? This would indicate that the input is skipping the files because it doesn't detect that they have changed.&lt;/LI&gt;
&lt;LI&gt;Are you sure that Splunk has access to the files you want it to monitor? The permission errors seen previously might be an indicator that Splunk doesn't have access to the files.&lt;/LI&gt;
&lt;LI&gt;You might try disabling the option to only include new results to see if you get the results you want.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 23 May 2017 17:33:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-installing-the-File-Directory-Information-Input-add-on-why/m-p/251833#M28879</guid>
      <dc:creator>LukeMurphey</dc:creator>
      <dc:date>2017-05-23T17:33:26Z</dc:date>
    </item>
  </channel>
</rss>

