Getting Data In

How to define a Windows monitor stanza containing a space in the path?

donnyintown
Engager

When defining a monitoring path in inputs.conf with space in the path, any Windows directory path with space in it is not working. There is a space in " Web Server Extensions". Is there a way defined monitoring path with a space in it? Other monitor inputs without spaces are working fine.

[monitor://C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\WebServices\LogFiles]
disabled = false
sourcetype = iis
index = infra_sharepoint
1 Solution

donnyintown
Engager

the issue is resolved after changing the sourcetype from iis to abciis.

View solution in original post

0 Karma

ttovar
Engager

My experience with Splunk v7.3 is that the [monitor] stanza understands 'spaces' as-is, i.e., nothing special needs to be done.

For instance, my 'inputs.conf' works correctly with the following:

[monitor://C:\Program Files (x86)\My App\Logs*\app.log*]

0 Karma

donnyintown
Engager

the issue is resolved after changing the sourcetype from iis to abciis.

0 Karma

BainM
Communicator

What does sourcetype have to do with spaces in the monitor:// statement? This answer is not helpful to me. I do not want to downvote it as it is not offensive, but it is not helpful either.

ttovar
Engager

I think this reply re source-type was voted Answer because the OP's problem was with source-type rather than the spaces in the file-name/path

0 Karma

Michael
Contributor

Can you clarify?

you mean you can just make up a sourcetype (and name it anything like "abciis")...?

Did you have to define "abciis" anywhere?

Did not work, as explained above.

0 Karma

HiroshiSatoh
Champion

It was be imported without any problems. Is the correct character code of the log file?

alt text

alt text

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...