<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Correct path to IIIS logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Correct-path-to-IIIS-logs/m-p/411435#M72845</link>
    <description>&lt;PRE&gt;&lt;CODE&gt;Sorry lost the backslahes. Here is the correct  directory structure.
E:\weblogs\w3svc1\*.log
E:\weblogs\w3svc2\*.log
E:\weblogs\w3svc3\*.log
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 25 May 2018 17:34:52 GMT</pubDate>
    <dc:creator>putrtek</dc:creator>
    <dc:date>2018-05-25T17:34:52Z</dc:date>
    <item>
      <title>Correct path to IIIS logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Correct-path-to-IIIS-logs/m-p/411434#M72844</link>
      <description>&lt;P&gt;Trying to setup the Universal Forwarder on the Web Server to forward IIS logs to SPLUNK.&lt;BR /&gt;
The Windows Event log ARE forwarding correctly. My IIS logs are NOT stored in the default location so I'm trying to figure out the correct stanza to use.&lt;/P&gt;

&lt;P&gt;My actual IIS log directoiry structure is &lt;BR /&gt;
    E:\weblogs\w3svc1*.log&lt;BR /&gt;
    E:\weblogs\w3svc2*.log&lt;BR /&gt;
    E:\weblogs\w3svc3*.log&lt;BR /&gt;
    Etc... multiple web sites&lt;/P&gt;

&lt;P&gt;I tried the following Stanzas neither have seemed to work&lt;/P&gt;

&lt;P&gt;[monitor://E:\weblogs\*\*.log]&lt;BR /&gt;
disabled  = 0&lt;/P&gt;

&lt;P&gt;[monitor://E:\weblogs\...\*.log]&lt;BR /&gt;
disabled  = 0&lt;/P&gt;

&lt;P&gt;I even tried tho log just a single site&lt;BR /&gt;
[monitor://E:\weblogs\w3svc1\*.log]&lt;BR /&gt;
disabled  = 0&lt;/P&gt;

&lt;P&gt;I restart splunk forwarded after changing the path&lt;BR /&gt;
If I run 'splunk list monitor' I get for all stanzas&lt;BR /&gt;
    E:\weblogs*.log&lt;/P&gt;

&lt;P&gt;No logs are being imported that I can tell&lt;/P&gt;

&lt;P&gt;Appreciate any assistsnce anyone can provide.&lt;/P&gt;

&lt;P&gt;-MARK-&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 17:31:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Correct-path-to-IIIS-logs/m-p/411434#M72844</guid>
      <dc:creator>putrtek</dc:creator>
      <dc:date>2018-05-25T17:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: Correct path to IIIS logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Correct-path-to-IIIS-logs/m-p/411435#M72845</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;Sorry lost the backslahes. Here is the correct  directory structure.
E:\weblogs\w3svc1\*.log
E:\weblogs\w3svc2\*.log
E:\weblogs\w3svc3\*.log
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 25 May 2018 17:34:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Correct-path-to-IIIS-logs/m-p/411435#M72845</guid>
      <dc:creator>putrtek</dc:creator>
      <dc:date>2018-05-25T17:34:52Z</dc:date>
    </item>
    <item>
      <title>Re: Correct path to IIIS logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Correct-path-to-IIIS-logs/m-p/411436#M72846</link>
      <description>&lt;P&gt;Did you verify the splunk process has permissions to the read the log files you want it to monitor?&lt;/P&gt;

&lt;P&gt;Do you see any events in the $SPLUNK_HOME\var\log\splunkd.log regarding these file monitors?&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 18:02:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Correct-path-to-IIIS-logs/m-p/411436#M72846</guid>
      <dc:creator>solarboyz1</dc:creator>
      <dc:date>2018-05-25T18:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: Correct path to IIIS logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Correct-path-to-IIIS-logs/m-p/411437#M72847</link>
      <description>&lt;P&gt;So is there a specific account that needs permissions?  I assume it's the account that the SplunkUniveralForwareder service is running under? I will go look in the $SPLUNK_HOME\var\log\splunkd.log to see if anything is there. Thanks for the advise.   -MARK-&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 19:04:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Correct-path-to-IIIS-logs/m-p/411437#M72847</guid>
      <dc:creator>putrtek</dc:creator>
      <dc:date>2018-05-25T19:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: Correct path to IIIS logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Correct-path-to-IIIS-logs/m-p/411438#M72848</link>
      <description>&lt;P&gt;Sorry it has taken me a while to respond to this. Been very busy on another project just got back to this today.&lt;BR /&gt;
The only entiries in my Splunkd.log are as follows&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;05-30-2018 11:52:38.167 -0400 INFO  TailingProcessor - Parsing configuration stanza: monitor://e:\WebLogs\*.log.
05-30-2018 11:52:38.167 -0400 INFO  TailingProcessor - Adding watch on path: e:\WebLogs.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I think these are both good&lt;/P&gt;

&lt;P&gt;Right now my SplunkForwarder Service is running under the Local System account. I haven't been able to figure out how to give that account READ permisssions to the e:\weblogs folder.&lt;/P&gt;

&lt;P&gt;-MARK-&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 16:25:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Correct-path-to-IIIS-logs/m-p/411438#M72848</guid>
      <dc:creator>putrtek</dc:creator>
      <dc:date>2018-05-30T16:25:54Z</dc:date>
    </item>
  </channel>
</rss>

