Getting Data In

Need input stanza for a shared drive

anandhalagarasa
Path Finder

Hi Team,

I have a following path which is located in a shared drive so how should i need to write the inputs.conf (monitor stanza)..

i.e
index=xyz
sourcetype=abc

So the full path for the log file folder would be:

M:\Local\orex\keen\Archive\Error_Path\

Here Local folder is a shared drive in between. So kindly help to provide the inputs.conf for the file.

0 Karma

harsmarvania57
Ultra Champion

Hi,

Have you tried M:\Local\orex\keen\Archive\Error_Path\ in monitor stanza in inputs.conf ? If yes then is it not working ?

0 Karma

anandhalagarasa
Path Finder

I have already tried the way which you have suggested but still logs were not getting ingested into Splunk. And also currently I have tried this one as well. Since the folder "Local" is a shared one but still its not working.

[monitor://\M:\Local\orex\keen\Archive\Error_Path]

Hence kindly help

0 Karma

harsmarvania57
Ultra Champion

Ok, I never tried this before but can you please run net use on command prompt on windows server and try to use Remote path in your monitor stanza ?

Have a look at comment by gkanapathy on https://answers.splunk.com/answers/1730/windows-mapped-drive-and-light-forwarding.html

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...