Getting Data In

How to define a Windows monitor stanza containing a space in the path?

donnyintown
Engager

When defining a monitoring path in inputs.conf with space in the path, any Windows directory path with space in it is not working. There is a space in " Web Server Extensions". Is there a way defined monitoring path with a space in it? Other monitor inputs without spaces are working fine.

[monitor://C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\WebServices\LogFiles]
disabled = false
sourcetype = iis
index = infra_sharepoint
1 Solution

donnyintown
Engager

the issue is resolved after changing the sourcetype from iis to abciis.

View solution in original post

0 Karma

ttovar
Engager

My experience with Splunk v7.3 is that the [monitor] stanza understands 'spaces' as-is, i.e., nothing special needs to be done.

For instance, my 'inputs.conf' works correctly with the following:

[monitor://C:\Program Files (x86)\My App\Logs*\app.log*]

0 Karma

donnyintown
Engager

the issue is resolved after changing the sourcetype from iis to abciis.

0 Karma

BainM
Communicator

What does sourcetype have to do with spaces in the monitor:// statement? This answer is not helpful to me. I do not want to downvote it as it is not offensive, but it is not helpful either.

ttovar
Engager

I think this reply re source-type was voted Answer because the OP's problem was with source-type rather than the spaces in the file-name/path

0 Karma

Michael
Contributor

Can you clarify?

you mean you can just make up a sourcetype (and name it anything like "abciis")...?

Did you have to define "abciis" anywhere?

Did not work, as explained above.

0 Karma

HiroshiSatoh
Champion

It was be imported without any problems. Is the correct character code of the log file?

alt text

alt text

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...