When we are trying to take Exchange logs using the below inputs.conf its getting an error, Any body help me on this
10-03-2019 15:44:09.088 +0400 ERROR TailingProcessor - Invalid value '0' for parameter 'time_before_close' in stanza 'monitor://C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\Logs\MessageTracking'. Will use default value (3).
[monitor://C:\Program Files\Microsoft\Exchange Server\V14\TransportRoles\Logs\MessageTracking]
disabled=false
index=EXCH
sourcetype=MSExch2013:Tracking
The setting must be coming from a different config file. What do you get when you run
splunk btool --debug inputs list "monitor://C:\Program Files\Microsoft\Exchange Server\V14\TransportRoles\Logs\MessageTracking"
its loading from Exchange App and I can not see any other monitor entries for the same path
If it is being defined inside the App, verified by running Rich's command above, check the app-dir/default/inputs.conf as well as the app-dir/local/inputs.conf. Besides, this is not an error as splunk ignores the wrong parameter.