<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: collect data from a folder, but it is a disk in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/collect-data-from-a-folder-but-it-is-a-disk/m-p/697567#M10363</link>
    <description>&lt;P&gt;Yes, it is a mistyping, in my inputs.conf i got it right.&lt;/P&gt;</description>
    <pubDate>Wed, 28 Aug 2024 09:11:18 GMT</pubDate>
    <dc:creator>Alex_Rus</dc:creator>
    <dc:date>2024-08-28T09:11:18Z</dc:date>
    <item>
      <title>collect data from a folder, but it is a disk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/collect-data-from-a-folder-but-it-is-a-disk/m-p/697476#M10355</link>
      <description>&lt;P&gt;I need to collect data from a folder on a Windows machine, the problem is that this folder is mounted as a disk and the host sends data to it. The classic inputs.conf for the folder source does not work. How can I fix this problem?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 15:27:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/collect-data-from-a-folder-but-it-is-a-disk/m-p/697476#M10355</guid>
      <dc:creator>Alex_Rus</dc:creator>
      <dc:date>2024-08-27T15:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: collect data from a folder, but it is a disk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/collect-data-from-a-folder-but-it-is-a-disk/m-p/697495#M10357</link>
      <description>&lt;P&gt;Tell us more.&amp;nbsp; What exactly do you mean by "does not work"?&amp;nbsp; What results/errors do you get?&amp;nbsp; What is the inputs.conf stanza for that input?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 16:48:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/collect-data-from-a-folder-but-it-is-a-disk/m-p/697495#M10357</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-08-27T16:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: collect data from a folder, but it is a disk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/collect-data-from-a-folder-but-it-is-a-disk/m-p/697499#M10358</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/271616"&gt;@Alex_Rus&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;if the disk is always mounted with the same name, you can put it in your inputs.conf:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor://E:\my_foler\my_files.log]&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 17:19:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/collect-data-from-a-folder-but-it-is-a-disk/m-p/697499#M10358</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-08-27T17:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: collect data from a folder, but it is a disk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/collect-data-from-a-folder-but-it-is-a-disk/m-p/697563#M10360</link>
      <description>&lt;P&gt;Hi, Giuseppe! Thank you for your answer.&lt;/P&gt;&lt;P&gt;Let me explain the situation. The application is configured to collect logs from four hosts, on two of which the data is collected in the internal storage C:\Program Files\Microsoft\Exchange Server\... and the data comes from these hosts correctly. On the other two hosts the data is collected in a folder that is moved to a separate disk&amp;nbsp;&lt;SPAN&gt;C:\MyFolder\MyFolder1\*.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;My stanza looks like:&lt;/P&gt;&lt;P&gt;[monitor://C:/MyFolder\MyFolder1/*]&lt;/P&gt;&lt;P&gt;disabled = 0&lt;/P&gt;&lt;P&gt;index = MyIndex1&lt;/P&gt;&lt;P&gt;sourcetype = MySourcetype1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[monitor://C:/Program Files/Microsoft/Exchange Server/.../*]&lt;/P&gt;&lt;P&gt;disabled = 0&lt;/P&gt;&lt;P&gt;index = MyIndex1&lt;/P&gt;&lt;P&gt;sourcetype = MySourcetype1&lt;SPAN&gt;#&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 09:03:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/collect-data-from-a-folder-but-it-is-a-disk/m-p/697563#M10360</guid>
      <dc:creator>Alex_Rus</dc:creator>
      <dc:date>2024-08-28T09:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: collect data from a folder, but it is a disk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/collect-data-from-a-folder-but-it-is-a-disk/m-p/697564#M10361</link>
      <description>&lt;P&gt;Hi, richgalloway! Thank you for your answer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wrote this information in response to the previous question from Giuseppe.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 09:05:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/collect-data-from-a-folder-but-it-is-a-disk/m-p/697564#M10361</guid>
      <dc:creator>Alex_Rus</dc:creator>
      <dc:date>2024-08-28T09:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: collect data from a folder, but it is a disk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/collect-data-from-a-folder-but-it-is-a-disk/m-p/697565#M10362</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/271616"&gt;@Alex_Rus&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I don't know if it's a mistyping, but you have to use backslashes in windows paths:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor://C:\MyFolder\MyFolder1\*]
disabled = 0
index = MyIndex1
sourcetype = MySourcetype1

[monitor://C:\Program Files\Microsoft\Exchange Server\...\*]
disabled = 0
index = MyIndex1
sourcetype = MySourcetype1#&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 09:05:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/collect-data-from-a-folder-but-it-is-a-disk/m-p/697565#M10362</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-08-28T09:05:57Z</dc:date>
    </item>
    <item>
      <title>Re: collect data from a folder, but it is a disk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/collect-data-from-a-folder-but-it-is-a-disk/m-p/697567#M10363</link>
      <description>&lt;P&gt;Yes, it is a mistyping, in my inputs.conf i got it right.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 09:11:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/collect-data-from-a-folder-but-it-is-a-disk/m-p/697567#M10363</guid>
      <dc:creator>Alex_Rus</dc:creator>
      <dc:date>2024-08-28T09:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: collect data from a folder, but it is a disk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/collect-data-from-a-folder-but-it-is-a-disk/m-p/697568#M10364</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/271616"&gt;@Alex_Rus&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;What's the problem?&lt;/P&gt;&lt;P&gt;you can have two different stanzas for your two different inputs with the same other parameters.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 09:23:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/collect-data-from-a-folder-but-it-is-a-disk/m-p/697568#M10364</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-08-28T09:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: collect data from a folder, but it is a disk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/collect-data-from-a-folder-but-it-is-a-disk/m-p/697570#M10365</link>
      <description>&lt;P&gt;the problem is that data from hosts where data is coming to a mounted disk does not come to Splunk&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 09:42:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/collect-data-from-a-folder-but-it-is-a-disk/m-p/697570#M10365</guid>
      <dc:creator>Alex_Rus</dc:creator>
      <dc:date>2024-08-28T09:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: collect data from a folder, but it is a disk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/collect-data-from-a-folder-but-it-is-a-disk/m-p/697572#M10367</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/271616"&gt;@Alex_Rus&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;what's the resul runnung from cmd:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;dir C:\MyFolder\MyFolder1\*&lt;/LI-CODE&gt;&lt;P&gt;?&lt;/P&gt;&lt;P&gt;if you haven't results, maybe the path isn't correct&lt;/P&gt;&lt;P&gt;or maybe there's another issue:&lt;/P&gt;&lt;P&gt;could data be equal to the ones from another input?&lt;/P&gt;&lt;P&gt;if they are the same, even if from a differen file, Splunk by default doesn't index a log twice.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 10:03:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/collect-data-from-a-folder-but-it-is-a-disk/m-p/697572#M10367</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-08-28T10:03:56Z</dc:date>
    </item>
  </channel>
</rss>

