Deployment Architecture

Gettin Error FileClassifierManager, TailReader, FilesystemChangeWatcher on SPLUNK Universal Forwarder

thatiana_liz
New Member

Hello,

I am trying to upload a .csv file and I am getting three errors messagen in my internal logs

" -0400 ERROR TailReader - error from
read call from "WARN
FilesystemChangeWatcher - error
getting attributes of path
"D:\Dados\SKY\Compartilhado\TECNOL~1\MONITO~1\TransUnion2Splunk\O0055TRANSUNION_COLETAFINALDESEMANA_30042020.csv":
Access is denied."

" WARN FileClassifierManager - Unable
to open
'D:\Dados\SKY\Compartilhado\TECNOL~1\MONITO~1\TransUnion2Splunk\O0055TRANSUNION_COLETAFINALDESEMANA_TESTE.CSV'"

ERROR TailReader - error from read
call from
'D:\Dados\SKY\Compartilhado\TECNOL~1\MONITO~1\TransUnion2Splunk\O0055TRANSUNION_COLETAFINALDESEMANA_TESTE.CSV'.

And the the file is not uploading into Splunk.

I checked the permision, it's correct.
The SPLUNK UF it's executing System Account

Can you please help me figure out why I am getting this error and my file is not getting indexed?

My inputs.conf

[monitor://D:\Dados\SKY\Compartilhado\TECNOL~1\MONITO~1\TransUnion2Splunk\O0055TRANSUNION_COLETAFINALDESEMANA_*.CSV]
_TCP_ROUTING =  *
index=INDEX
source=INDEXXX:XXX
sourcetype=INDEXXX:XXX
disabled = 0
time_before_close = 60
multiline_event_extra_waittime = true
initCrcLength = 512
0 Karma

PavelP
Motivator

Hello @thatiana_liz ,

please check this answer: https://answers.splunk.com/answers/147511/filesystemchangewatcher-error-getting-attributes-of-path.h...

you need not only read permissions for the CSV file, but also "list folder content" permissions for all folders.

Let me know if it worked

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...