Getting Data In

How to define a Windows monitor stanza containing a space in the path?

donnyintown
Engager

When defining a monitoring path in inputs.conf with space in the path, any Windows directory path with space in it is not working. There is a space in " Web Server Extensions". Is there a way defined monitoring path with a space in it? Other monitor inputs without spaces are working fine.

[monitor://C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\WebServices\LogFiles]
disabled = false
sourcetype = iis
index = infra_sharepoint
1 Solution

donnyintown
Engager

the issue is resolved after changing the sourcetype from iis to abciis.

View solution in original post

0 Karma

ttovar
Engager

My experience with Splunk v7.3 is that the [monitor] stanza understands 'spaces' as-is, i.e., nothing special needs to be done.

For instance, my 'inputs.conf' works correctly with the following:

[monitor://C:\Program Files (x86)\My App\Logs*\app.log*]

0 Karma

donnyintown
Engager

the issue is resolved after changing the sourcetype from iis to abciis.

0 Karma

BainM
Communicator

What does sourcetype have to do with spaces in the monitor:// statement? This answer is not helpful to me. I do not want to downvote it as it is not offensive, but it is not helpful either.

ttovar
Engager

I think this reply re source-type was voted Answer because the OP's problem was with source-type rather than the spaces in the file-name/path

0 Karma

Michael
Contributor

Can you clarify?

you mean you can just make up a sourcetype (and name it anything like "abciis")...?

Did you have to define "abciis" anywhere?

Did not work, as explained above.

0 Karma

HiroshiSatoh
Champion

It was be imported without any problems. Is the correct character code of the log file?

alt text

alt text

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...