Getting Data In

How do I Monitor a UNC path?

seanlon11
Path Finder

From server1, I have access to the desired UNC path, and this same user is running splunk, so I know access is not an issue.

\etc\apps\search\local\inputs.conf

[monitor://\\SANCIFS_TDC_NETAPP01A.SAN.MyCompany.Com\CIFS_COGNOS$\Test\Logs]
disabled = false
host = sancifs_test
index = default
sourcetype = motio_test

I have tried many different permutations of the forward and back slash for my monitor stanza, but nothing has worked so far.

What am I doing wrong?

Thanks, Sean

Tags (1)
1 Solution

seanlon11
Path Finder

dang, that is going to make me mad. I set the Service to run as a different user, and it now works. (figuring out the syntax of how to get Windows to recognize the user was quite a chore)

View solution in original post

0 Karma

seanlon11
Path Finder

dang, that is going to make me mad. I set the Service to run as a different user, and it now works. (figuring out the syntax of how to get Windows to recognize the user was quite a chore)

0 Karma

Paolo_Prigione
Builder

Is the indexer (or forwarder) a linux or window box?
If windows, might it be that the "local system account" under which splunk runs by default has no access to that folder?
Uhm, is that a dollar sign after COGNOS? Is it supported in paths?

0 Karma

seanlon11
Path Finder

1) Yes, I have restarted Splunk after updating the inputs.conf

2) Splunk 4.1.1 (build 78281)

3) 14 files

0 Karma

Genti
Splunk Employee
Splunk Employee

few standard questions: 1- Have you restarted splunk after changing the config file? 2 - what version of splunk are you using? how many files are in the Logs directory?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...