<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can i index the log file from a windows smtp service? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126723#M26083</link>
    <description>&lt;P&gt;Did you install the Universal Forwarder to run as a user with access to the files/directory you need? You don't need to do anything with the props.conf file right now.&lt;/P&gt;</description>
    <pubDate>Mon, 27 Jan 2014 16:43:55 GMT</pubDate>
    <dc:creator>gkanapathy</dc:creator>
    <dc:date>2014-01-27T16:43:55Z</dc:date>
    <item>
      <title>How can i index the log file from a windows smtp service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126722#M26082</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;After a lot of searching, trying and bashing my head, i will drop my problem here. I would like to index the logfiles of a windows smtp service. I thought this would be easy, however I can't get it to work.&lt;/P&gt;

&lt;P&gt;Splunk is installed on a debian along with some other tools. So to index Windows files, I need to install the universal forwarder. I installed version 6, so the Splunk_TA_windows is installed too. During the installation I cannot browse to &lt;CODE&gt;c:\windows\System32\logfiles&lt;/CODE&gt;. It's not there. I can browse to the folder in Windows explorer... Ok, no problem, I select a directory to monitor and i will change it in inputs.conf. &lt;/P&gt;

&lt;P&gt;I understand that i should edit&lt;BR /&gt;&lt;BR /&gt;
&lt;CODE&gt;C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\local\inputs.conf.&lt;/CODE&gt; It does not matter what i try, if I add &lt;CODE&gt;c:\windows\System32\logfiles&lt;/CODE&gt;, the folder is not getting indexed. Any other folder will be indexed.&lt;/P&gt;

&lt;P&gt;What is so special about this folder?&lt;BR /&gt;
I see that Splunk also indexes the eventlog (system, security and application) how can I remove these? During the installation i made sure nothing was selected. I only want the folder to be indexed.&lt;BR /&gt;
How do I make sure that the indexed info is not stored in the main index. I would like an index per server. Or is that a bad idea. I seems easy to remove an index when a server no longer exits.&lt;/P&gt;

&lt;P&gt;The logfiles are in IIS format. I read some articles that Splunk can handle this, but I would need to change the props file. Is that the file on the forwarder or on the indexer?&lt;/P&gt;

&lt;P&gt;Thanks for any ideas,&lt;BR /&gt;
Sven&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:43:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126722#M26082</guid>
      <dc:creator>svendewindt</dc:creator>
      <dc:date>2020-09-28T15:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: How can i index the log file from a windows smtp service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126723#M26083</link>
      <description>&lt;P&gt;Did you install the Universal Forwarder to run as a user with access to the files/directory you need? You don't need to do anything with the props.conf file right now.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2014 16:43:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126723#M26083</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2014-01-27T16:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: How can i index the log file from a windows smtp service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126724#M26084</link>
      <description>&lt;P&gt;I installed the Universal Forwarder with domain admin credentials. I can browse to the folder in windows without issues...&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2014 19:10:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126724#M26084</guid>
      <dc:creator>svendewindt</dc:creator>
      <dc:date>2014-01-27T19:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: How can i index the log file from a windows smtp service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126725#M26085</link>
      <description>&lt;P&gt;are any errors showing up in your _internal index?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2014 23:30:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126725#M26085</guid>
      <dc:creator>mkinsley_splunk</dc:creator>
      <dc:date>2014-01-29T23:30:58Z</dc:date>
    </item>
    <item>
      <title>Re: How can i index the log file from a windows smtp service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126726#M26086</link>
      <description>&lt;P&gt;oh , i'm not sure if this is just a typo in your question, but from what I can see the logfiles directory is CamelCase :&lt;/P&gt;

&lt;P&gt;System32\LogFiles\  , not System32\logfiles&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2014 23:34:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126726#M26086</guid>
      <dc:creator>mkinsley_splunk</dc:creator>
      <dc:date>2014-01-29T23:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: How can i index the log file from a windows smtp service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126727#M26087</link>
      <description>&lt;P&gt;I'm not that familiar with splunk. Where can i find the errors in the _internal index?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2014 10:26:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126727#M26087</guid>
      <dc:creator>svendewindt</dc:creator>
      <dc:date>2014-01-30T10:26:07Z</dc:date>
    </item>
    <item>
      <title>Re: How can i index the log file from a windows smtp service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126728#M26088</link>
      <description>&lt;P&gt;I would like to add, that when change the UniversalForwarder service to run under .\administrator then the files that i manually add to c:\windows\System32\logfiles are getting indexed. The log files, created by the smtp service however or not indexed. So that rules out any typo. &lt;/P&gt;

&lt;P&gt;It seems to be related to ntfs rights. I checked the rights and they look correct. Just to be sure i forced the inheritance again. Still, the manually added files are indexed, the log files created by the smtp service are not indexed.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2014 10:31:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126728#M26088</guid>
      <dc:creator>svendewindt</dc:creator>
      <dc:date>2014-01-30T10:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: How can i index the log file from a windows smtp service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126729#M26089</link>
      <description>&lt;P&gt;The splunk logs are located in &lt;CODE&gt;splunk\var\log\splunk\&lt;/CODE&gt;.  The log file you're interested in is the &lt;CODE&gt;splunkd.log&lt;/CODE&gt;.&lt;BR /&gt;
If there is a problem with the indexing or reading of that log file, then you should be able to search the &lt;CODE&gt;_internal&lt;/CODE&gt; logs for messages about the file.  Example:&lt;BR /&gt;
&lt;CODE&gt;index=_internal "*LogFileName*"&lt;/CODE&gt;&lt;BR /&gt;
For LogFileName just use the name of the smtp logfile, no need to put the whole path.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2014 19:00:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126729#M26089</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-02-11T19:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: How can i index the log file from a windows smtp service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126730#M26090</link>
      <description>&lt;P&gt;It sounds like it might be a permissions issue to me.&lt;/P&gt;

&lt;P&gt;As an administrator, you have access to that directory.  As the local system account, you might not.&lt;/P&gt;

&lt;P&gt;I would try creating an account with local permissions to that directory and running the UniversalForwarder service under that account.&lt;/P&gt;

&lt;P&gt;As a quick test, you can have it run under your credentials or under the credentials of an administrator.  If it works, all you need to do is add a service account.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2014 22:14:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126730#M26090</guid>
      <dc:creator>thesteve</dc:creator>
      <dc:date>2014-02-11T22:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: How can i index the log file from a windows smtp service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126731#M26091</link>
      <description>&lt;P&gt;Occasionally Windows files will not update their timestamp, or will not be readable while the writing process still has it open. You can try setting &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;alwaysOpenFile = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;to the monitor stanza in inputs.conf and see if that helps.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2014 23:14:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126731#M26091</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2014-02-11T23:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: How can i index the log file from a windows smtp service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126732#M26092</link>
      <description>&lt;P&gt;Indeed. If I run the UniversalForwarder as an administrator, the files are getting indexed. I will create a service account.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2014 08:23:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126732#M26092</guid>
      <dc:creator>svendewindt</dc:creator>
      <dc:date>2014-02-12T08:23:51Z</dc:date>
    </item>
    <item>
      <title>Re: How can i index the log file from a windows smtp service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126733#M26093</link>
      <description>&lt;P&gt;This seems like an excellent tip. I can imagine, you should always set this for windows service logfiles.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2014 08:25:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126733#M26093</guid>
      <dc:creator>svendewindt</dc:creator>
      <dc:date>2014-02-12T08:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: How can i index the log file from a windows smtp service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126734#M26094</link>
      <description>&lt;P&gt;Also, when troubleshooting permission issues - ProcMon from Sysinternals is gold.&lt;BR /&gt;
&lt;A href="https://technet.microsoft.com/en-us/library/bb896645.aspx"&gt;https://technet.microsoft.com/en-us/library/bb896645.aspx&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Filter it to only show "Result"=ACCESS DENIED and "Proccess Name" begins with: splunk&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2015 15:27:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126734#M26094</guid>
      <dc:creator>bravon</dc:creator>
      <dc:date>2015-04-16T15:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: How can i index the log file from a windows smtp service?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126735#M26095</link>
      <description>&lt;P&gt;check the tailing status of that directory:&lt;/P&gt;

&lt;P&gt;Open a browser to:&lt;BR /&gt;
&lt;A href="https://serverwithuniversalforwarder:8089/services/admin/inputstatus/TailingProcessor%3AFileStatus"&gt;https://serverwithuniversalforwarder:8089/services/admin/inputstatus/TailingProcessor%3AFileStatus&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2015 15:30:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-i-index-the-log-file-from-a-windows-smtp-service/m-p/126735#M26095</guid>
      <dc:creator>aalanisr26</dc:creator>
      <dc:date>2015-04-16T15:30:21Z</dc:date>
    </item>
  </channel>
</rss>

