Getting Data In

Accessing SharePoint directories using UNC: Why splunkd.log shows "Monitoring file or directory that doesn't exist at startup time"?

DonDandrea
Path Finder

I am trying to use fschange to monitor some SharePoint directories. As a user on my remote forwarder box I can access the directories. I am logged onto the server using the same domain account that splunkd uses. When I enable the fschange monitoring I get the following message in the splunkd.log.

08-08-2014 09:17:41.259 -0400 WARN FSChangeMonitor - Monitoring file or directory that doesn't exist at startup time

any help you could provide would be greatly appreciated.

Thank you
Don

Tags (3)
0 Karma
1 Solution

DonDandrea
Path Finder

We never found a solution to this problem. The data is stored in a SQL database. You can access the data using a UNC path from a windows workstation or server but SharePoint is rendering the output. Splunk does not access the data in the same way and SharePoint is not rendering the data for Splunk. We considered going after the data directly from the DB but Microsoft discourages that. In the end our solution will be to send the data someplace other than SharePoint.

View solution in original post

0 Karma

DonDandrea
Path Finder

We never found a solution to this problem. The data is stored in a SQL database. You can access the data using a UNC path from a windows workstation or server but SharePoint is rendering the output. Splunk does not access the data in the same way and SharePoint is not rendering the data for Splunk. We considered going after the data directly from the DB but Microsoft discourages that. In the end our solution will be to send the data someplace other than SharePoint.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...