Getting Data In

How to define a Windows monitor stanza containing a space in the path?

donnyintown
Engager

When defining a monitoring path in inputs.conf with space in the path, any Windows directory path with space in it is not working. There is a space in " Web Server Extensions". Is there a way defined monitoring path with a space in it? Other monitor inputs without spaces are working fine.

[monitor://C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\WebServices\LogFiles]
disabled = false
sourcetype = iis
index = infra_sharepoint
1 Solution

donnyintown
Engager

the issue is resolved after changing the sourcetype from iis to abciis.

View solution in original post

0 Karma

ttovar
Engager

My experience with Splunk v7.3 is that the [monitor] stanza understands 'spaces' as-is, i.e., nothing special needs to be done.

For instance, my 'inputs.conf' works correctly with the following:

[monitor://C:\Program Files (x86)\My App\Logs*\app.log*]

0 Karma

donnyintown
Engager

the issue is resolved after changing the sourcetype from iis to abciis.

0 Karma

BainM
Communicator

What does sourcetype have to do with spaces in the monitor:// statement? This answer is not helpful to me. I do not want to downvote it as it is not offensive, but it is not helpful either.

ttovar
Engager

I think this reply re source-type was voted Answer because the OP's problem was with source-type rather than the spaces in the file-name/path

0 Karma

Michael
Contributor

Can you clarify?

you mean you can just make up a sourcetype (and name it anything like "abciis")...?

Did you have to define "abciis" anywhere?

Did not work, as explained above.

0 Karma

HiroshiSatoh
Champion

It was be imported without any problems. Is the correct character code of the log file?

alt text

alt text

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...