Deployment Architecture

Gettin Error FileClassifierManager, TailReader, FilesystemChangeWatcher on SPLUNK Universal Forwarder

thatiana_liz
New Member

Hello,

I am trying to upload a .csv file and I am getting three errors messagen in my internal logs

" -0400 ERROR TailReader - error from
read call from "WARN
FilesystemChangeWatcher - error
getting attributes of path
"D:\Dados\SKY\Compartilhado\TECNOL~1\MONITO~1\TransUnion2Splunk\O0055TRANSUNION_COLETAFINALDESEMANA_30042020.csv":
Access is denied."

" WARN FileClassifierManager - Unable
to open
'D:\Dados\SKY\Compartilhado\TECNOL~1\MONITO~1\TransUnion2Splunk\O0055TRANSUNION_COLETAFINALDESEMANA_TESTE.CSV'"

ERROR TailReader - error from read
call from
'D:\Dados\SKY\Compartilhado\TECNOL~1\MONITO~1\TransUnion2Splunk\O0055TRANSUNION_COLETAFINALDESEMANA_TESTE.CSV'.

And the the file is not uploading into Splunk.

I checked the permision, it's correct.
The SPLUNK UF it's executing System Account

Can you please help me figure out why I am getting this error and my file is not getting indexed?

My inputs.conf

[monitor://D:\Dados\SKY\Compartilhado\TECNOL~1\MONITO~1\TransUnion2Splunk\O0055TRANSUNION_COLETAFINALDESEMANA_*.CSV]
_TCP_ROUTING =  *
index=INDEX
source=INDEXXX:XXX
sourcetype=INDEXXX:XXX
disabled = 0
time_before_close = 60
multiline_event_extra_waittime = true
initCrcLength = 512
0 Karma

PavelP
Motivator

Hello @thatiana_liz ,

please check this answer: https://answers.splunk.com/answers/147511/filesystemchangewatcher-error-getting-attributes-of-path.h...

you need not only read permissions for the CSV file, but also "list folder content" permissions for all folders.

Let me know if it worked

0 Karma
Get Updates on the Splunk Community!

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...