Getting Data In

How to set up log file monitoring on a Windows universal forwarder?

mkaplan1979
New Member

I'm trying to set up .log file monitoring so splunk would pull the context of the .log files in to the indexer and nothing i try seems to work.....
Can someone please help? I'm a newbie at this whole splunk thing

0 Karma
1 Solution

MuS
Legend

Hi mkaplan1979,

you're using *nix path name convention on a Windows machine. Your input should like this:

[monitor://D:\logfiles\log123.log]

maybe something like this:

[monitor://C:\pos\TKAgent\Location Agents\log\]

Hope this helps ...

cheers, MuS

View solution in original post

MuS
Legend

Hi mkaplan1979,

you're using *nix path name convention on a Windows machine. Your input should like this:

[monitor://D:\logfiles\log123.log]

maybe something like this:

[monitor://C:\pos\TKAgent\Location Agents\log\]

Hope this helps ...

cheers, MuS

mkaplan1979
New Member

thank you MuS it worked!

0 Karma

mkaplan1979
New Member

this is inputs.conf on the forwarder

[default]
host = MPK005-Server

[script://$SPLUNK_HOME\bin\scripts\splunk-wmi.path]
disabled = 0

[monitor://pos/log/]
disabled = false
sourcetype = syslog
index = pos

[monitor://pos/TKAgent/Location Agents/log/]
disabled = false
sourcetype = syslog
index = pos

0 Karma

mkaplan1979
New Member

UF is on windows as well. I'll post what I've tried in a minute

0 Karma

mkaplan1979
New Member

BTW I'm running splunk enterprise on windows and using universal forwarder on the client

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What have you tried so far? Is the UF client Linux or Windows?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...