<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why my Windows logs don't reach Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294587#M96081</link>
    <description>&lt;P&gt;From - &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0/Data/Specifyinputpathswithwildcards"&gt;http://docs.splunk.com/Documentation/Splunk/6.0/Data/Specifyinputpathswithwildcards&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Caution: In Windows, you cannot currently use a wildcard at the root level. For example, this does not work:&lt;/P&gt;

&lt;P&gt;[monitor://E:...\foo\*.log]&lt;BR /&gt;
Splunk Enterprise logs an error and fails to index the desired files.&lt;/P&gt;

&lt;P&gt;This is a known issue, described in the Known Issues topic of the Release Notes. Look there for details on all known issues.&lt;/P&gt;

&lt;P&gt;This might have been fixed in later versions, I'm not sure.&lt;/P&gt;</description>
    <pubDate>Fri, 10 Feb 2017 20:02:47 GMT</pubDate>
    <dc:creator>pradeepkumarg</dc:creator>
    <dc:date>2017-02-10T20:02:47Z</dc:date>
    <item>
      <title>Why my Windows logs don't reach Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294578#M96072</link>
      <description>&lt;P&gt;We see the following - &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;02-09-2017 21:12:49.973 -0600 INFO  TailingProcessor - Parsing configuration stanza: monitor://E:\logs\sessiondelete\*_DELETESCRIPT.log.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And -&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;02-09-2017 21:12:49.973 -0600 INFO  TailingProcessor - Adding watch on path: E:\logs\sessiondelete.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But they don't reach the indexers. Any ideas?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 16:44:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294578#M96072</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-02-10T16:44:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why my Windows logs don't reach Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294579#M96073</link>
      <description>&lt;P&gt;follow the steps from the below url, &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.2/Troubleshooting/Cantfinddata"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.2/Troubleshooting/Cantfinddata&lt;/A&gt; . &lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 16:47:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294579#M96073</guid>
      <dc:creator>vasanthmss</dc:creator>
      <dc:date>2017-02-10T16:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why my Windows logs don't reach Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294580#M96074</link>
      <description>&lt;P&gt;Great link - the only thing that I don't know is whether the forwarder can access this Windows folder ...&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 16:57:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294580#M96074</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-02-10T16:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why my Windows logs don't reach Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294581#M96075</link>
      <description>&lt;P&gt;&lt;A href="https://technet.microsoft.com/en-us/sysinternals"&gt;Sysinternals&lt;/A&gt; tool &lt;A href="https://technet.microsoft.com/en-us/sysinternals/bb896653"&gt;Process Explorer&lt;/A&gt; can easily find out if your UF has that file open.&lt;/P&gt;

&lt;P&gt;Open Process Explorer, click the binoculars, search for E:\whatever in there.  If the UF has the file open, it'll be listed.  &lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 17:50:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294581#M96075</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2017-02-10T17:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: Why my Windows logs don't reach Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294582#M96076</link>
      <description>&lt;P&gt;Windows doesn't play well with wild cards on the monitor path. Try using whiteliest and blacklist instead to wild card your file names.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 19:21:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294582#M96076</guid>
      <dc:creator>pradeepkumarg</dc:creator>
      <dc:date>2017-02-10T19:21:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why my Windows logs don't reach Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294583#M96077</link>
      <description>&lt;P&gt;Seriously? do you have any docs about it, by any chance? &lt;/P&gt;

&lt;P&gt;I see the following  at &lt;A href="https://docs.splunk.com/Documentation/Splunk/6.5.2/Data/Specifyinputpathswithwildcards"&gt;Specify input paths with wildcards&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2473iA939A8C95D8AE888/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 19:24:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294583#M96077</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-02-10T19:24:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why my Windows logs don't reach Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294584#M96078</link>
      <description>&lt;P&gt;Check for error like access denied on the splunkd.log on the forwarder (for that file).&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 19:44:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294584#M96078</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-02-10T19:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why my Windows logs don't reach Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294585#M96079</link>
      <description>&lt;P&gt;The only references to &lt;CODE&gt;DELETESCRIPT&lt;/CODE&gt; in &lt;CODE&gt;splunkd.log&lt;/CODE&gt; are the two at the beginning of this thread...&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 19:49:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294585#M96079</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-02-10T19:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why my Windows logs don't reach Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294586#M96080</link>
      <description>&lt;P&gt;The forwarder should be sending _internal data to Indexers, do you at least see that (to confirm that outputs.conf is configured correctly, check index=_internal host=yourForwarder ). Also, restart your forwarder and check the splunkd.log for errors and warning, you may catch something relevant. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:49:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294586#M96080</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2020-09-29T12:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: Why my Windows logs don't reach Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294587#M96081</link>
      <description>&lt;P&gt;From - &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0/Data/Specifyinputpathswithwildcards"&gt;http://docs.splunk.com/Documentation/Splunk/6.0/Data/Specifyinputpathswithwildcards&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Caution: In Windows, you cannot currently use a wildcard at the root level. For example, this does not work:&lt;/P&gt;

&lt;P&gt;[monitor://E:...\foo\*.log]&lt;BR /&gt;
Splunk Enterprise logs an error and fails to index the desired files.&lt;/P&gt;

&lt;P&gt;This is a known issue, described in the Known Issues topic of the Release Notes. Look there for details on all known issues.&lt;/P&gt;

&lt;P&gt;This might have been fixed in later versions, I'm not sure.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2017 20:02:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294587#M96081</guid>
      <dc:creator>pradeepkumarg</dc:creator>
      <dc:date>2017-02-10T20:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: Why my Windows logs don't reach Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294588#M96082</link>
      <description>&lt;P&gt;Gorgeous - it worked now. Please convert the comment to an answer so I can accept it...&lt;/P&gt;</description>
      <pubDate>Sat, 11 Feb 2017 00:30:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294588#M96082</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-02-11T00:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: Why my Windows logs don't reach Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294589#M96083</link>
      <description>&lt;P&gt;Glad it helped..&lt;/P&gt;</description>
      <pubDate>Sat, 11 Feb 2017 00:47:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294589#M96083</guid>
      <dc:creator>pradeepkumarg</dc:creator>
      <dc:date>2017-02-11T00:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: Why my Windows logs don't reach Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294590#M96084</link>
      <description>&lt;P&gt;Very much appreciated!!! &lt;/P&gt;</description>
      <pubDate>Sat, 11 Feb 2017 00:57:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-my-Windows-logs-don-t-reach-Splunk/m-p/294590#M96084</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-02-11T00:57:00Z</dc:date>
    </item>
  </channel>
</rss>

