Getting Data In

How do I Monitor a UNC path?

seanlon11
Path Finder

From server1, I have access to the desired UNC path, and this same user is running splunk, so I know access is not an issue.

\etc\apps\search\local\inputs.conf

[monitor://\\SANCIFS_TDC_NETAPP01A.SAN.MyCompany.Com\CIFS_COGNOS$\Test\Logs]
disabled = false
host = sancifs_test
index = default
sourcetype = motio_test

I have tried many different permutations of the forward and back slash for my monitor stanza, but nothing has worked so far.

What am I doing wrong?

Thanks, Sean

Tags (1)
1 Solution

seanlon11
Path Finder

dang, that is going to make me mad. I set the Service to run as a different user, and it now works. (figuring out the syntax of how to get Windows to recognize the user was quite a chore)

View solution in original post

0 Karma

seanlon11
Path Finder

dang, that is going to make me mad. I set the Service to run as a different user, and it now works. (figuring out the syntax of how to get Windows to recognize the user was quite a chore)

0 Karma

Paolo_Prigione
Builder

Is the indexer (or forwarder) a linux or window box?
If windows, might it be that the "local system account" under which splunk runs by default has no access to that folder?
Uhm, is that a dollar sign after COGNOS? Is it supported in paths?

0 Karma

seanlon11
Path Finder

1) Yes, I have restarted Splunk after updating the inputs.conf

2) Splunk 4.1.1 (build 78281)

3) 14 files

0 Karma

Genti
Splunk Employee
Splunk Employee

few standard questions: 1- Have you restarted splunk after changing the config file? 2 - what version of splunk are you using? how many files are in the Logs directory?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...