All Apps and Add-ons

Why is my inputs.conf monitor stanza on a local file directory in my Windows universal forwarder not picking up data?

Path Finder

I am trying to use a Universal Forwarder to monitor some local files. I am editing the file $SPLUNK_HOME\etc\apps\Splunk_TA_windows\local\inputs.conf , adding the following statement:

[monitor:///.../*.txt]
index = main
recursive = false
disabled = 0

It is my understanding that this will search the root directory and all sub-directories for any text files. Am I missing something? I haven't seen any new data appear on my Indexer.

0 Karma

Splunk Employee
Splunk Employee

That looks like a Unix file path, not Windows. Since I see this is within the Windows TA, shouldn't the path start with c:\ ?

Splunk Employee
Splunk Employee

There should be a backslash after the colon (website formatting nonsense)

0 Karma

Path Finder

I changed that now, so that it is
[monitor://c:...*.txt]
and still no luck.

0 Karma