<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Network folder monitoring in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678968#M113466</link>
    <description>&lt;P&gt;Permissions issue?&lt;/P&gt;</description>
    <pubDate>Wed, 28 Feb 2024 12:27:59 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2024-02-28T12:27:59Z</dc:date>
    <item>
      <title>Network folder monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678764#M113424</link>
      <description>&lt;P&gt;Hello Splunker&lt;BR /&gt;&lt;BR /&gt;In my request, I want to monitor the below files, which are under the network folder. I have configured indexes.conf, props.conf, inputs.conf &amp;amp; transforms.conf but nothing is working for me to get data into Splunk. Please check my config and help or suggest me if any changes are required.&lt;/P&gt;&lt;P&gt;inputs.conf :&lt;/P&gt;&lt;P&gt;[monitor://\\WALVAU-SCADA-1\d$\CM\alarmreports\outgoing*]&lt;BR /&gt;disabled = false&lt;BR /&gt;index = scada&lt;BR /&gt;host = WALVAU-SCADA-1&lt;BR /&gt;sourcetype = cm_scada_xml&lt;/P&gt;&lt;P&gt;indexes.conf :&lt;/P&gt;&lt;P&gt;[scada]&lt;BR /&gt;coldPath = $SPLUNK_DB/scada/colddb&lt;BR /&gt;enableDataIntegrityControl = 0&lt;BR /&gt;enableTsidxReduction = 0&lt;BR /&gt;homePath = $SPLUNK_DB/scada/db&lt;BR /&gt;maxTotalDataSizeMB = 512000&lt;BR /&gt;thawedPath = $SPLUNK_DB/scada/thaweddb&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;props.conf :&lt;/P&gt;&lt;P&gt;[cm_scada_xml]&lt;BR /&gt;KEEP_EMPTY_VALS = false&lt;BR /&gt;KV_MODE = xml&lt;BR /&gt;LINE_BREAKER = &amp;lt;\/eqtext:EquipmentEvent&amp;gt;()&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD = 24&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;SEDCMD-first = s/^.*&amp;lt;eqtext:EquipmentEvent/&amp;lt;eqtext:EquipmentEvent/g&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;TIME_FORMAT = %Y-%m-%dT%H:%M:%S.%3f%Z&lt;BR /&gt;TIME_PREFIX = ((?&amp;lt;!ReceiverFmInstanceName&amp;gt;))&amp;lt;eqtext:EventTime&amp;gt;&lt;BR /&gt;TRUNCATE = 100000000&lt;BR /&gt;category = Custom&lt;BR /&gt;disabled = false&lt;BR /&gt;pulldown_type = true&lt;BR /&gt;TRANSFORMS-remove-xml-footer = remove-xml-footer&lt;BR /&gt;TRANSFORMS-keep-came-in-and-went-out-states = keep-came-in-and-went-out-states&lt;BR /&gt;FIELDALIAS-fields_scada_xml = "eqtext:EquipmentEvent.eqtext:ID.eqtext:Location.eqtext:PhysicalLocation.AreaID" AS area "eqtext:EquipmentEvent.eqtext:ID.eqtext:Location.eqtext:PhysicalLocation.ElementID" AS element "eqtext:EquipmentEvent.eqtext:ID.eqtext:Location.eqtext:PhysicalLocation.EquipmentID" AS equipment "eqtext:EquipmentEvent.eqtext:ID.eqtext:Location.eqtext:PhysicalLocation.ZoneID" AS zone "eqtext:EquipmentEvent.eqtext:ID.eqtext:Description" AS description "eqtext:EquipmentEvent.eqtext:ID.eqtext:MIS_Address" AS mis_address "eqtext:EquipmentEvent.eqtext:Detail.State" AS state "eqtext:EquipmentEvent.eqtext:Detail.eqtext:EventTime" AS event_time "eqtext:EquipmentEvent.eqtext:Detail.eqtext:MsgNr" AS msg_nr "eqtext:EquipmentEvent.eqtext:Detail.eqtext:OperatorID" AS operator_id "eqtext:EquipmentEvent.eqtext:Detail.ErrorType" AS error_type "eqtext:EquipmentEvent.eqtext:Detail.Severity" AS severity&lt;/P&gt;&lt;P&gt;transforms.conf :&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;[remove-xml-footer]&lt;BR /&gt;REGEX = &amp;lt;\/eqtexo:EquipmentEventReport&amp;gt;&lt;BR /&gt;DEST_KEY = queue&lt;BR /&gt;FORMAT = nullQueue&lt;/P&gt;&lt;P&gt;[keep-came-in-and-went-out-states]&lt;BR /&gt;REGEX = &amp;lt;State&amp;gt;(?!CAME_IN|WENT_OUT).*?&amp;lt;\/State&amp;gt;&lt;BR /&gt;DEST_KEY = queue&lt;BR /&gt;FORMAT = nullQueue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1709010398970.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29497i99B82279DF7F79A9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1709010398970.png" alt="uagraw01_0-1709010398970.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 05:11:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678764#M113424</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-02-27T05:11:34Z</dc:date>
    </item>
    <item>
      <title>Re: Network folder monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678765#M113425</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;please could you better describe your architecture?&lt;/P&gt;&lt;P&gt;have you a stand alone Splunk server?&lt;/P&gt;&lt;P&gt;have you a Forwarder or folders to monitor are accessed by the Splunk server?&lt;/P&gt;&lt;P&gt;which user are you usig to run Splunk on the the system accessing the folders to monior? have this user the grants to read the files?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 05:49:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678765#M113425</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-02-27T05:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: Network folder monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678768#M113426</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;I have a standalone Windows Splunk server, and from the same server I can able to access the network folder as provided in the screenshot earlier.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 06:14:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678768#M113426</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-02-27T06:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: Network folder monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678771#M113427</link>
      <description>&lt;P&gt;Ingesting files over the network from CIFS share can be tricky.&lt;/P&gt;&lt;P&gt;1) Too many monitored files cause performance issues (but that might be an issue when it works in the first place)&lt;/P&gt;&lt;P&gt;2) The user the splunkd.exe process runs with must be able to access the share. Since there is no additional authentication possible it works only in a domain environment if you run the forwarder process under domain account and grant this account proper permissions to the share (could also work - never tried it - if the share was public but that's not a good idea).&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 07:15:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678771#M113427</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-02-27T07:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: Network folder monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678775#M113430</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;please try to use this header in the inputs.conf stanza:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor://\\WALVAU-SCADA-1\d$\CM\alarmreports\outgoing\*.xml]&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 08:08:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678775#M113430</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-02-27T08:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: Network folder monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678776#M113431</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&amp;nbsp;I have already tested by adding the below string to the monitoring stranza. But no luck was found.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 08:18:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678776#M113431</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-02-27T08:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Network folder monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678779#M113432</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;said, check if the user you're using to run Splunk has the grants to access the shared folder,&lt;/P&gt;&lt;P&gt;Then think to use a Universal Forwarder on the server that has the shared folder: is more sure and efficient.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 08:23:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678779#M113432</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-02-27T08:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: Network folder monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678788#M113434</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Till to 10/30/2023 we received the events by using the same approach but the same I am using the same configuration settings but nothing worked at all.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1709024653930.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29499iA4E7D16A89005CBA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1709024653930.png" alt="uagraw01_0-1709024653930.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 09:06:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678788#M113434</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-02-27T09:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: Network folder monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678799#M113435</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If there are too many files in that folder you can try adding "&lt;SPAN&gt;ignoreOlderThan"&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;setting in monitor stanza;&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor://\\WALVAU-SCADA-1\d$\CM\alarmreports\outgoing*]
disabled = false
index = scada
host = WALVAU-SCADA-1
sourcetype = cm_scada_xml
ignoreOlderThan = 24h&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 27 Feb 2024 10:33:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678799#M113435</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2024-02-27T10:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: Network folder monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678802#M113437</link>
      <description>&lt;P&gt;Anyway, regardless of the reason, if it used to work and stop, it would be prudent to troubleshoot for the cause instead of blindly trying to add a setting here and there.&lt;/P&gt;&lt;P&gt;Check your splunkd.log on the forwarder for errors. Check output of&lt;/P&gt;&lt;PRE&gt;splunk list inputstatus&lt;/PRE&gt;&lt;P&gt;and&lt;/P&gt;&lt;PRE&gt;splunk list monitor&lt;/PRE&gt;</description>
      <pubDate>Tue, 27 Feb 2024 10:40:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678802#M113437</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-02-27T10:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: Network folder monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678806#M113438</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/70277"&gt;@uagraw01&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;probably something changed!&lt;BR /&gt;analyze from scratch the input, starting from thetimestamp, that I dont see where it comes from.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 11:04:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678806#M113438</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-02-27T11:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: Network folder monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678813#M113442</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;&amp;nbsp;I tried but No luck found.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 12:15:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678813#M113442</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-02-27T12:15:36Z</dc:date>
    </item>
    <item>
      <title>Re: Network folder monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678814#M113443</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;I have changed my approach. I have used one script which copy the files from the network folder and paste it to local folder and changed the monitoring stranza in inputs.conf but this also not worked. Below I changed in inputs.conf&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[monitor://C:\Windows\Temp\outgoing\*.xml]
disabled = false
index = new_demo_scada
host = VIDI
sourcetype = new_demo_scada&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;props &amp;amp; transform remains same.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 13:05:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678814#M113443</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-02-27T13:05:03Z</dc:date>
    </item>
    <item>
      <title>Re: Network folder monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678838#M113448</link>
      <description>&lt;P&gt;OK.&lt;/P&gt;&lt;P&gt;1. I assume you restarted the UF after doing all those config changes.&lt;/P&gt;&lt;P&gt;2. Do you get any other data from this forwarder?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 13:48:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678838#M113448</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-02-27T13:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: Network folder monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678841#M113449</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;I restarted the Splunk standalone server where I put the files.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 13:58:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678841#M113449</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-02-27T13:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: Network folder monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678962#M113465</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I am getting below issues while executing your suggested command "splunk list inputstatus" . Can you please tell me what issue you can see by referring to below screenshot?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1709122518567.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29534iCC04B2B234D3DDC1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1709122518567.png" alt="uagraw01_0-1709122518567.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 12:17:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678962#M113465</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-02-28T12:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: Network folder monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678968#M113466</link>
      <description>&lt;P&gt;Permissions issue?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 12:27:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678968#M113466</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-02-28T12:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: Network folder monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678969#M113467</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;Does the highlighted things are related to permission related issue ?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 12:32:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678969#M113467</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-02-28T12:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: Network folder monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678977#M113468</link>
      <description>&lt;P&gt;See further up if there are any files from those directories listed.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 13:39:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678977#M113468</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-02-28T13:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: Network folder monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678989#M113470</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Below is a screenshot of test server files being perfectly monitored in Splunk. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_2-1709127956720.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29543i75A80D2EC2C87608/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_2-1709127956720.png" alt="uagraw01_2-1709127956720.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Below screenshot belongs to production server and the same file creating an issue for monitoring in Splunk(issued server).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_3-1709127978706.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29544i4A2FAF8179E97EA3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_3-1709127978706.png" alt="uagraw01_3-1709127978706.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 13:46:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Network-folder-monitoring/m-p/678989#M113470</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-02-28T13:46:46Z</dc:date>
    </item>
  </channel>
</rss>

