<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to monitor a windows file. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-monitor-a-windows-file/m-p/679613#M113564</link>
    <description>&lt;P&gt;I'm collecting papercut logs from a window server.&lt;/P&gt;&lt;P&gt;[monitor://&lt;SPAN&gt;C:\Program Files\PaperCut MF\server\logs\print-logs\printlog_*.log&lt;/SPAN&gt;]&lt;/P&gt;&lt;P&gt;disable=false&lt;/P&gt;&lt;P&gt;the output and index are applied via a deployment server.&lt;/P&gt;&lt;P&gt;searching with index=* host=&amp;lt;hostname&amp;gt;&lt;/P&gt;&lt;P&gt;splunkforwarder service account has read on the folder and children.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Mar 2024 16:02:35 GMT</pubDate>
    <dc:creator>dspencer</dc:creator>
    <dc:date>2024-03-05T16:02:35Z</dc:date>
    <item>
      <title>Unable to monitor a windows file.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-monitor-a-windows-file/m-p/679315#M113522</link>
      <description>&lt;P&gt;What are some reasons why a UF wouldn't monitor a windows file assuming there is nothing wrong with any configs and the virtual account has full access to the file I'm trying to monitor?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 16:23:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-monitor-a-windows-file/m-p/679315#M113522</guid>
      <dc:creator>dspencer</dc:creator>
      <dc:date>2024-03-01T16:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to monitor a windows file.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-monitor-a-windows-file/m-p/679319#M113524</link>
      <description>&lt;P&gt;Those are the two main reasons.&amp;nbsp; Are you sure the assumptions are valid?&amp;nbsp; Have you checked splunkd.log on the UF?&amp;nbsp; What makes you think it's a monitor problem?&amp;nbsp; Could it be a search problem?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 16:51:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-monitor-a-windows-file/m-p/679319#M113524</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-03-01T16:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to monitor a windows file.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-monitor-a-windows-file/m-p/679334#M113527</link>
      <description>&lt;P&gt;Thanks for your reply. I'm not 100% sure my assumptions are correct but the config is pretty simple. I'm the admin and I did give the splunk virtual account full permissions. I am searching all indexes for a specific host. The splunk log do have errors but the only lines associated with the file in question are file is parsed and watched. The UF is collecting eventlogs and UF logs. What are some other factors I can look at?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 18:59:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-monitor-a-windows-file/m-p/679334#M113527</guid>
      <dc:creator>dspencer</dc:creator>
      <dc:date>2024-03-01T18:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to monitor a windows file.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-monitor-a-windows-file/m-p/679372#M113531</link>
      <description>&lt;P&gt;If you're not sure about the assumptions then consider sharing the inputs.conf stanza so others can check it for you.&lt;/P&gt;&lt;P&gt;Can you search for other data sources from the same UF?&amp;nbsp; Is the monitored file being updated?&lt;/P&gt;&lt;P&gt;How are you trying to search for the data?&amp;nbsp; Try using &lt;FONT face="courier new,courier"&gt;earliest=-1y latest=+1y&lt;/FONT&gt; in case timestamps are incorrect.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Mar 2024 13:20:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-monitor-a-windows-file/m-p/679372#M113531</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-03-02T13:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to monitor a windows file.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-monitor-a-windows-file/m-p/679613#M113564</link>
      <description>&lt;P&gt;I'm collecting papercut logs from a window server.&lt;/P&gt;&lt;P&gt;[monitor://&lt;SPAN&gt;C:\Program Files\PaperCut MF\server\logs\print-logs\printlog_*.log&lt;/SPAN&gt;]&lt;/P&gt;&lt;P&gt;disable=false&lt;/P&gt;&lt;P&gt;the output and index are applied via a deployment server.&lt;/P&gt;&lt;P&gt;searching with index=* host=&amp;lt;hostname&amp;gt;&lt;/P&gt;&lt;P&gt;splunkforwarder service account has read on the folder and children.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 16:02:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-monitor-a-windows-file/m-p/679613#M113564</guid>
      <dc:creator>dspencer</dc:creator>
      <dc:date>2024-03-05T16:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to monitor a windows file.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-monitor-a-windows-file/m-p/679787#M113595</link>
      <description>&lt;P&gt;That monitor stanza name looks OK. I hope the stanza itself contains &lt;FONT face="courier new,courier"&gt;index=&lt;/FONT&gt; and &lt;FONT face="courier new,courier"&gt;sourcetype=&lt;/FONT&gt; settings.&lt;/P&gt;&lt;P&gt;Perhaps the hostname is not what you expect.&amp;nbsp; Try this search&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=&amp;lt;&amp;lt;index name from inputs.conf&amp;gt;&amp;gt; sourcetype=&amp;lt;&amp;lt;sourcetype name from inputs.conf&amp;gt;&amp;gt; source=*printlog_*.log earliest=-1d latest=+1y&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Have you confirmed other logs from the same UF are indexed?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 12:35:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-monitor-a-windows-file/m-p/679787#M113595</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-03-06T12:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to monitor a windows file.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-monitor-a-windows-file/m-p/679822#M113600</link>
      <description>&lt;P&gt;I am collecting all other logs except the papercut from this specific host. The provided query doesn't return anything. I am sure that the service account has read access to the file. What are some other things I can look into that would prevent the UF from collecting a windows file if everything splunk related is correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again, thanks for the assistance.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 15:27:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-monitor-a-windows-file/m-p/679822#M113600</guid>
      <dc:creator>dspencer</dc:creator>
      <dc:date>2024-03-06T15:27:57Z</dc:date>
    </item>
  </channel>
</rss>

