<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File/Directory Information Input not working in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/File-Directory-Information-Input-not-working/m-p/540391#M90489</link>
    <description>&lt;P&gt;Did you restart the forwarder after installing the app and modifying the inputs.conf file?&lt;/P&gt;&lt;P&gt;-Yes&lt;/P&gt;&lt;P&gt;Do you see the forwarder's internal logs (splunkd.log, etc.)?&lt;/P&gt;&lt;P&gt;-Yes&lt;/P&gt;&lt;P&gt;When you see no logs, how exactly are you trying to find them?&lt;/P&gt;&lt;P&gt;-On the UF directly: C:\Program Files\SplunkUniversalForwarder\var\log\splunk&lt;/P&gt;</description>
    <pubDate>Thu, 18 Feb 2021 14:13:29 GMT</pubDate>
    <dc:creator>logtastic</dc:creator>
    <dc:date>2021-02-18T14:13:29Z</dc:date>
    <item>
      <title>File/Directory Information Input not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/File-Directory-Information-Input-not-working/m-p/540298#M90484</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have installed the&amp;nbsp;File/Directory Information Input add-on to a Windows endpoint to test monitoring certain files. The Windows host has Python 2.x installed and I am having Splunk monitor a "test.txt" file under&amp;nbsp;C:\Program Files\SplunkUniversalForwarder - so we theoretically shouldn't have any permission issues - please correct me if I am wrong.&lt;/P&gt;&lt;P&gt;The only change to the add-on was creating a local directory with a inputs.conf file:&lt;/P&gt;&lt;P&gt;[file_meta_data://default]&lt;BR /&gt;file_path = C:\Program Files\SplunkUniversalForwarder&lt;BR /&gt;interval = 1m&lt;BR /&gt;recurse = 1&lt;BR /&gt;only_if_changed = 1&lt;BR /&gt;include_file_hash = 0&lt;BR /&gt;file_hash_limit = 500MB&lt;BR /&gt;file_filter= test&lt;BR /&gt;index = main&lt;/P&gt;&lt;P&gt;I am seeing no logs, whats also interesting is that I am not seeing the&amp;nbsp;&lt;SPAN&gt;file_meta_data_modular_input.log file either.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Where am I going wrong?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 18:39:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/File-Directory-Information-Input-not-working/m-p/540298#M90484</guid>
      <dc:creator>logtastic</dc:creator>
      <dc:date>2021-02-17T18:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: File/Directory Information Input not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/File-Directory-Information-Input-not-working/m-p/540388#M90488</link>
      <description>&lt;P&gt;Did you restart the forwarder after installing the app and modifying the inputs.conf file?&lt;/P&gt;&lt;P&gt;Do you see the forwarder's internal logs (splunkd.log, etc.)?&lt;/P&gt;&lt;P&gt;When you see no logs, how exactly are you trying to find them?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 14:08:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/File-Directory-Information-Input-not-working/m-p/540388#M90488</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-02-18T14:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: File/Directory Information Input not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/File-Directory-Information-Input-not-working/m-p/540391#M90489</link>
      <description>&lt;P&gt;Did you restart the forwarder after installing the app and modifying the inputs.conf file?&lt;/P&gt;&lt;P&gt;-Yes&lt;/P&gt;&lt;P&gt;Do you see the forwarder's internal logs (splunkd.log, etc.)?&lt;/P&gt;&lt;P&gt;-Yes&lt;/P&gt;&lt;P&gt;When you see no logs, how exactly are you trying to find them?&lt;/P&gt;&lt;P&gt;-On the UF directly: C:\Program Files\SplunkUniversalForwarder\var\log\splunk&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 14:13:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/File-Directory-Information-Input-not-working/m-p/540391#M90489</guid>
      <dc:creator>logtastic</dc:creator>
      <dc:date>2021-02-18T14:13:29Z</dc:date>
    </item>
  </channel>
</rss>

