Deployment Architecture

Gettin Error FileClassifierManager, TailReader, FilesystemChangeWatcher on SPLUNK Universal Forwarder

thatiana_liz
New Member

Hello,

I am trying to upload a .csv file and I am getting three errors messagen in my internal logs

" -0400 ERROR TailReader - error from
read call from "WARN
FilesystemChangeWatcher - error
getting attributes of path
"D:\Dados\SKY\Compartilhado\TECNOL~1\MONITO~1\TransUnion2Splunk\O0055TRANSUNION_COLETAFINALDESEMANA_30042020.csv":
Access is denied."

" WARN FileClassifierManager - Unable
to open
'D:\Dados\SKY\Compartilhado\TECNOL~1\MONITO~1\TransUnion2Splunk\O0055TRANSUNION_COLETAFINALDESEMANA_TESTE.CSV'"

ERROR TailReader - error from read
call from
'D:\Dados\SKY\Compartilhado\TECNOL~1\MONITO~1\TransUnion2Splunk\O0055TRANSUNION_COLETAFINALDESEMANA_TESTE.CSV'.

And the the file is not uploading into Splunk.

I checked the permision, it's correct.
The SPLUNK UF it's executing System Account

Can you please help me figure out why I am getting this error and my file is not getting indexed?

My inputs.conf

[monitor://D:\Dados\SKY\Compartilhado\TECNOL~1\MONITO~1\TransUnion2Splunk\O0055TRANSUNION_COLETAFINALDESEMANA_*.CSV]
_TCP_ROUTING =  *
index=INDEX
source=INDEXXX:XXX
sourcetype=INDEXXX:XXX
disabled = 0
time_before_close = 60
multiline_event_extra_waittime = true
initCrcLength = 512
0 Karma

PavelP
Motivator

Hello @thatiana_liz ,

please check this answer: https://answers.splunk.com/answers/147511/filesystemchangewatcher-error-getting-attributes-of-path.h...

you need not only read permissions for the CSV file, but also "list folder content" permissions for all folders.

Let me know if it worked

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...