Getting Data In

How to add / mount a folder?

neilmac64
Path Finder

I am running Splunk in Docker on my local machine. I would like to monitor a directory folder also on my local machine where data will be posted (csv files which I would like to index).

I go to:

  • Data Inputs > Files and Directories > Add New
    • File or Directory

If I use Browse, I can't find my directory - assume as it isn't mounted.

If I add the path to the folder, I get an error saying "This path does not exist or is not accessible."

It seems it should be easy to add a folder for monitoring - as yet I can't find a way to do it.

Can anyone point me in the right direction?

Many thanks in advance.

 

NM

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

This seems like a Docker problem(?) not a Splunk problem - you need to set up your Docker instance to have access to your local machine file system. Given that the essence of Docker is containment, this sounds like a non-trivial task!

PickleRick
SplunkTrust
SplunkTrust

Other way to go around the problem would be to install UF in the "main" system and forward events read by UF into the dockerized Splunk instance.

0 Karma

neilmac64
Path Finder

How do you do it in a non-docker environment?

Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

That depends on how your non-Docker environment is set up. I use WSL on my PC which automatically mounts the C drive under /mnt and is therefore easy to find.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...