All Apps and Add-ons

Adding Windows monitors via Linux CLI

davideddleman
New Member

Our central Splunk server is Linux, running (now) the latest as I suspected there was a bug involved in this situation. I've deployed the Windows universal forwarder to a bunch of Windows Server 2008 machines, and due to a known bug in the installer (as shown to me by Splunk support) they had to be installed with no options, and configured after. Since there are a lot of machines, I'm attempting to automate everything.

Whenever I attempt to add in a monitor via the splunk command on our Linux server, I get an error. This is what it is:
splunk add monitor -uri https://:8089 -auth
In handler 'monitor': Parameter name: Path does not exist.

It sounds like the monitor is only validated against what's valid for the local OS. Is this expected behavior or a bug? I've attempted the usual UNIX tricks -- encased the path in quotes, escaped the special characters, etc.

0 Karma

lukejadamec
Super Champion

Hi lukejadamec, this is not completely true .... you can use the CLI from the indexer to add a monitor on the forwarder. It's just not allowed by default - you must enable allowRemoteLogin in the server.conf of the forwarder. After that you can add a monitor remotely. BTW, with exception of the start, stop, restart, status and version command, all that control the splunkd, you can run all CLI commands remotely.

lukejadamec
Super Champion

Thanks MuS.

MuS
SplunkTrust
SplunkTrust

Hi lukejadamec, this is not completely true .... you can use the CLI from the indexer to add a monitor on the forwarder. It's just not allowed by default - you must enable allowRemoteLogin in the server.conf of the forwarder. After that you can add a monitor remotely. BTW, with exception of the start, stop, restart, status and version command, all that control the splunkd, you can run all CLI commands remotely.

davideddleman
New Member

Note that I'm not entering the path as . That's just how the Answers section formatted it.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...