Getting Data In

Monitor Windows DHCP log file

atifshaukat
New Member

I have setup input to index DHCP log files from remote server but unable to see any data being collected or collectors appearing on main page.

Under manage\Datainputs i have done following settings set source is Monitor a File or Directory Path to the server is something like this \servername\d$\abc.log

Tags (3)
0 Karma

ftk
Motivator

What account are you running splunk as? Local System or a domain account? Since you are attempting to access an admin share (\servername\d$) the account splunk runs under has to be an admin on the remote server. You may be better off creating a share on your remote server and granting read access to the Splunk service account, or install a splunk regular or light forwarder on the remote server to forward the logs to your indexer.

0 Karma

ftk
Motivator

Local admin or a domain account?

0 Karma

atifshaukat
New Member

splunk service is running as admin account and have full access to server so it is definitely no permission issue.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...