<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Error adding SSHFS mount as a data input in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Error-adding-SSHFS-mount-as-a-data-input/m-p/15056#M6740</link>
    <description>&lt;P&gt;on a mac os x server, I am trying to add a directory as input. I encounter the following error when trying to save the Monitor&lt;/P&gt;

&lt;P&gt;"Encountered the following error while trying to save: In handler 'monitor': Path is not readable."&lt;/P&gt;

&lt;P&gt;the path is /Volumes/wliprod02, and I can access this path as my local admin user. The volume is mounted via sshfs. &lt;/P&gt;

&lt;P&gt;splunkd is running as root user. so it should have access..
I cant see any error being logged to splunkd.log in conjunction with that&lt;/P&gt;

&lt;P&gt;Not sure what is wrong, any insight is appreciated!&lt;/P&gt;</description>
    <pubDate>Tue, 08 Jun 2010 16:11:33 GMT</pubDate>
    <dc:creator>frank_h</dc:creator>
    <dc:date>2010-06-08T16:11:33Z</dc:date>
    <item>
      <title>Error adding SSHFS mount as a data input</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Error-adding-SSHFS-mount-as-a-data-input/m-p/15056#M6740</link>
      <description>&lt;P&gt;on a mac os x server, I am trying to add a directory as input. I encounter the following error when trying to save the Monitor&lt;/P&gt;

&lt;P&gt;"Encountered the following error while trying to save: In handler 'monitor': Path is not readable."&lt;/P&gt;

&lt;P&gt;the path is /Volumes/wliprod02, and I can access this path as my local admin user. The volume is mounted via sshfs. &lt;/P&gt;

&lt;P&gt;splunkd is running as root user. so it should have access..
I cant see any error being logged to splunkd.log in conjunction with that&lt;/P&gt;

&lt;P&gt;Not sure what is wrong, any insight is appreciated!&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2010 16:11:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Error-adding-SSHFS-mount-as-a-data-input/m-p/15056#M6740</guid>
      <dc:creator>frank_h</dc:creator>
      <dc:date>2010-06-08T16:11:33Z</dc:date>
    </item>
    <item>
      <title>Re: Error adding SSHFS mount as a data input</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Error-adding-SSHFS-mount-as-a-data-input/m-p/15057#M6741</link>
      <description>&lt;P&gt;One of the things to check when feeding Splunk an SSHFS mount to monitor is that the underlying mount point directory also has adequate ownership/permissions.&lt;/P&gt;

&lt;P&gt;We have seen instances where the directories traversed were all showing the expected owner/permissions with the SSHFS share mounted (root:root/750 for example) but Splunk was unable to monitor the files in the share because the underlying mount point belonged to a different user.&lt;/P&gt;

&lt;P&gt;This will show up in $SPLUNK_HOME/var/log/splunkd.log in the following way :&lt;/P&gt;

&lt;P&gt;splunkd.log:06-27-2010 11:37:02.229 INFO TailingProcessor - Parsing configuration stanza: monitor:///var/log/sshfs_mountpoint.
splunkd.log:06-27-2010 11:37:02.229 WARN FilesystemChangeWatcher - error getting attributes of path "/var/log/sshfs_mountpoint": Permission denied&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2010 02:33:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Error-adding-SSHFS-mount-as-a-data-input/m-p/15057#M6741</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2010-07-02T02:33:01Z</dc:date>
    </item>
  </channel>
</rss>

