<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: When i check logfile and found process cannot access the file because it is being.Is there any solution for this? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/When-i-check-logfile-and-found-process-cannot-access-the-file/m-p/762462#M120717</link>
    <description>&lt;P&gt;I stumbled across this while trying to find a solution to some UFs that have gone haywire and decided to try to monitor a bunch of files exactly like pagefile.sys, which of course is silly and doesn't work.&lt;/P&gt;&lt;P&gt;btool says nothing's *told* it to try to monitor those.&lt;/P&gt;&lt;P&gt;I'm going to have them try to restart one of the affected UFs; something's going on and I'll update here when I find out what in case others stumble across this problem.&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jul 2026 18:41:52 GMT</pubDate>
    <dc:creator>Richfez</dc:creator>
    <dc:date>2026-07-23T18:41:52Z</dc:date>
    <item>
      <title>When i check logfile and found process cannot access the file because it is being.Is there any solution for this?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-i-check-logfile-and-found-process-cannot-access-the-file/m-p/551857#M91586</link>
      <description>&lt;P&gt;WARN FilesystemChangeWatcher - error getting attributes of path "C:\pagefile.sys": The process cannot access the file because it is being used by another process.&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 11:42:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-i-check-logfile-and-found-process-cannot-access-the-file/m-p/551857#M91586</guid>
      <dc:creator>ravivasant</dc:creator>
      <dc:date>2021-05-17T11:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: When i check logfile and found process cannot access the file because it is being.Is there any solution for this?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-i-check-logfile-and-found-process-cannot-access-the-file/m-p/551915#M91597</link>
      <description>&lt;P&gt;What do you expect to do with pagefile.sys in Splunk? That's the OS swap file, probably locked exclusively and hence not accessible by any other process. Plus, it is a binary file and thus not really suitable for ingestion into Splunk.&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 18:11:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-i-check-logfile-and-found-process-cannot-access-the-file/m-p/551915#M91597</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2021-05-17T18:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: When i check logfile and found process cannot access the file because it is being.Is there any solution for this?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-i-check-logfile-and-found-process-cannot-access-the-file/m-p/762462#M120717</link>
      <description>&lt;P&gt;I stumbled across this while trying to find a solution to some UFs that have gone haywire and decided to try to monitor a bunch of files exactly like pagefile.sys, which of course is silly and doesn't work.&lt;/P&gt;&lt;P&gt;btool says nothing's *told* it to try to monitor those.&lt;/P&gt;&lt;P&gt;I'm going to have them try to restart one of the affected UFs; something's going on and I'll update here when I find out what in case others stumble across this problem.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 18:41:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-i-check-logfile-and-found-process-cannot-access-the-file/m-p/762462#M120717</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2026-07-23T18:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: When i check logfile and found process cannot access the file because it is being.Is there any solution for this?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-i-check-logfile-and-found-process-cannot-access-the-file/m-p/762466#M120719</link>
      <description>&lt;P&gt;Notoce that this is&amp;nbsp; not a monitor input. This is from a fschange input. While - if we are to believe the conf spec file - this input type has been deprecated since Splunk 5 (sic!) modern Splunk still comes with at least one fschange input on $SPLUNK_HOME defined by default.&lt;/P&gt;&lt;P&gt;Have you checked your config for any other fschange inputs?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 19:30:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-i-check-logfile-and-found-process-cannot-access-the-file/m-p/762466#M120719</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-07-23T19:30:26Z</dc:date>
    </item>
  </channel>
</rss>

