<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fschange with universal Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/fschange-with-universal-Forwarder/m-p/78353#M16031</link>
    <description>&lt;P&gt;Hey, thanks for your answer, but that's a typo on my behalf, any query I use to search does not bring any results (I'll edit the question with the right search parameters though thanks for pointing it out)&lt;/P&gt;</description>
    <pubDate>Wed, 03 Oct 2012 13:51:49 GMT</pubDate>
    <dc:creator>SplunkUser5888</dc:creator>
    <dc:date>2012-10-03T13:51:49Z</dc:date>
    <item>
      <title>fschange with universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/fschange-with-universal-Forwarder/m-p/78348#M16026</link>
      <description>&lt;P&gt;Hey guys, I've seen a couple of similar questions to mine but nothing has helped. I have a very simple edit in the inputs.conf of my Universal Forwarder on a Windows Server.&lt;BR /&gt;
It has in it;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[default]
host = server2003-splu
[fschange:C:\Program Files\]
index = _audit
signedaudit = false
#pollPeriod = 1
#hashMaxSize = 10485760
#fullEvent = true

[script://$SPLUNK_HOME\bin\scripts\splunk-perfmon.path]
disabled = 0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any reason why when i do a search&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_audit sourcetype=fs_notification host=server2003-splu
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;it doesn't come back with anything even after adding, changing and deleting files and folders in the Program Files directory?&lt;/P&gt;

&lt;P&gt;Thanks for any help you can give me&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2012 12:26:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/fschange-with-universal-Forwarder/m-p/78348#M16026</guid>
      <dc:creator>SplunkUser5888</dc:creator>
      <dc:date>2012-10-03T12:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: fschange with universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/fschange-with-universal-Forwarder/m-p/78349#M16027</link>
      <description>&lt;P&gt;No one knows how I can change my file to make it work? I don't mind rewriting it if someone thinks it needs to be changed completely&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2012 13:35:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/fschange-with-universal-Forwarder/m-p/78349#M16027</guid>
      <dc:creator>SplunkUser5888</dc:creator>
      <dc:date>2012-10-03T13:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: fschange with universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/fschange-with-universal-Forwarder/m-p/78350#M16028</link>
      <description>&lt;P&gt;The sourcetype should be &lt;CODE&gt;fs_notification&lt;/CODE&gt;, not &lt;CODE&gt;fs_notifications&lt;/CODE&gt;. Also you have a typo in the stanza below (diasbled instead of disabled), though that shouldn't affect the fschange stanza.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2012 13:43:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/fschange-with-universal-Forwarder/m-p/78350#M16028</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-10-03T13:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: fschange with universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/fschange-with-universal-Forwarder/m-p/78351#M16029</link>
      <description>&lt;P&gt;Your question was posted only an hour ago. You can't expect people doing this on their spare time to always see and respond to the question immediately...&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2012 13:44:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/fschange-with-universal-Forwarder/m-p/78351#M16029</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-10-03T13:44:43Z</dc:date>
    </item>
    <item>
      <title>Re: fschange with universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/fschange-with-universal-Forwarder/m-p/78352#M16030</link>
      <description>&lt;P&gt;sorry, I didn't mean to sound pushy&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2012 13:50:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/fschange-with-universal-Forwarder/m-p/78352#M16030</guid>
      <dc:creator>SplunkUser5888</dc:creator>
      <dc:date>2012-10-03T13:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: fschange with universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/fschange-with-universal-Forwarder/m-p/78353#M16031</link>
      <description>&lt;P&gt;Hey, thanks for your answer, but that's a typo on my behalf, any query I use to search does not bring any results (I'll edit the question with the right search parameters though thanks for pointing it out)&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2012 13:51:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/fschange-with-universal-Forwarder/m-p/78353#M16031</guid>
      <dc:creator>SplunkUser5888</dc:creator>
      <dc:date>2012-10-03T13:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: fschange with universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/fschange-with-universal-Forwarder/m-p/78354#M16032</link>
      <description>&lt;P&gt;It works now. Same config, same search nothing changed. It was a stupid mistake after all, the Universal Forwarder was not being restarted properly.&lt;/P&gt;

&lt;P&gt;Answer:&lt;/P&gt;

&lt;P&gt;Make sure you restart the server properly&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;C:\Program Files\SplunkUniversalForwarder\bin&amp;gt;splunk.exe restart
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 04 Oct 2012 12:29:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/fschange-with-universal-Forwarder/m-p/78354#M16032</guid>
      <dc:creator>SplunkUser5888</dc:creator>
      <dc:date>2012-10-04T12:29:50Z</dc:date>
    </item>
  </channel>
</rss>

