<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows log file data is not coming in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Windows-log-file-data-is-not-coming/m-p/674867#M112945</link>
    <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.2/Admin/Inputsconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.2/Admin/Inputsconf&lt;/A&gt;&lt;/P&gt;&lt;PRE&gt;[MonitorNoHandle://&amp;lt;path&amp;gt;]

* This input intercepts file writes to the specific file.&lt;/PRE&gt;&lt;P&gt;It appears this monitor config does not read the file itself but only intercepts what is about to be written to the file.&amp;nbsp; Your image shows last modified as Jan 4th which is your stated last ingest.&lt;/P&gt;&lt;P&gt;I think your configuration will only capture future content and not existing content.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jan 2024 18:23:12 GMT</pubDate>
    <dc:creator>dural_yyz</dc:creator>
    <dc:date>2024-01-19T18:23:12Z</dc:date>
    <item>
      <title>Windows log file data is not coming</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-log-file-data-is-not-coming/m-p/674808#M112935</link>
      <description>&lt;P&gt;hai&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have configured below log file stanza but not getting data into splunk from windows UF&lt;/P&gt;&lt;P&gt;having latest on Jan 4th but those data also not came&amp;nbsp;&lt;BR /&gt;is any parameter need to add ?&lt;/P&gt;&lt;P&gt;below is the config file&amp;nbsp;&lt;/P&gt;&lt;P&gt;[monitorNoHandle://C:\Program Files\Crestron\CCS400\User\Logs\CCSFirmwareUpdate.txt]&lt;BR /&gt;index=Testindx&lt;BR /&gt;sourcetype=test_sourcetype&lt;BR /&gt;disabled=0&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 09:56:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-log-file-data-is-not-coming/m-p/674808#M112935</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2024-01-19T09:56:06Z</dc:date>
    </item>
    <item>
      <title>Re: Windows log file data is not coming</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-log-file-data-is-not-coming/m-p/674811#M112936</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I suppose that you already configured outputs.conf and that you're already reeving logs from that machine.&lt;/P&gt;&lt;P&gt;Please try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor://C:\Program Files\Crestron\CCS400\User\Logs\CCSFirmwareUpdate.txt]
index=Testindx
sourcetype=test_sourcetype
disabled=0&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 10:03:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-log-file-data-is-not-coming/m-p/674811#M112936</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-01-19T10:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: Windows log file data is not coming</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-log-file-data-is-not-coming/m-p/674815#M112937</link>
      <description>&lt;P&gt;1. Do you get _any_ data from this forwarder? Especially events into _internal index.&lt;/P&gt;&lt;P&gt;2. Do you see any errors in c:\program files\splunk (or SplunkUniversalForwarder, depending on version)\var\log\splunk\splunkd.log on the forwarder?&lt;/P&gt;&lt;P&gt;3. What is the output of&lt;/P&gt;&lt;PRE&gt;splunk list monitor&lt;/PRE&gt;&lt;P&gt;and&lt;/P&gt;&lt;PRE&gt;splunk list inputstatus&lt;/PRE&gt;&lt;P&gt;run on your UF?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 10:17:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-log-file-data-is-not-coming/m-p/674815#M112937</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-01-19T10:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: Windows log file data is not coming</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-log-file-data-is-not-coming/m-p/674840#M112941</link>
      <description>&lt;P&gt;still not coming&amp;nbsp;&lt;/P&gt;&lt;P&gt;the file is text file as below and its under&amp;nbsp;Program Files\Crestron\CCS400\User\Logs\&lt;/P&gt;&lt;P&gt;and want to ingest the file&amp;nbsp;CCSFirmwareUpdate.txt&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sekhar463_0-1705673163212.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29031i5BF34E0E3023BA9E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sekhar463_0-1705673163212.png" alt="sekhar463_0-1705673163212.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 14:07:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-log-file-data-is-not-coming/m-p/674840#M112941</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2024-01-19T14:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: Windows log file data is not coming</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-log-file-data-is-not-coming/m-p/674841#M112942</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;which user are you using to run Splunk, has this user the grants to read this file?&lt;/P&gt;&lt;P&gt;please check that the path of the file is correct, runing the dir command in a cmd window.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 14:11:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-log-file-data-is-not-coming/m-p/674841#M112942</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-01-19T14:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: Windows log file data is not coming</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-log-file-data-is-not-coming/m-p/674867#M112945</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.2/Admin/Inputsconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.2/Admin/Inputsconf&lt;/A&gt;&lt;/P&gt;&lt;PRE&gt;[MonitorNoHandle://&amp;lt;path&amp;gt;]

* This input intercepts file writes to the specific file.&lt;/PRE&gt;&lt;P&gt;It appears this monitor config does not read the file itself but only intercepts what is about to be written to the file.&amp;nbsp; Your image shows last modified as Jan 4th which is your stated last ingest.&lt;/P&gt;&lt;P&gt;I think your configuration will only capture future content and not existing content.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2024 18:23:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-log-file-data-is-not-coming/m-p/674867#M112945</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2024-01-19T18:23:12Z</dc:date>
    </item>
  </channel>
</rss>

