Getting Data In

Problem with network logs

Bliide
Path Finder

I setup a data input from a network source. They are IIS logs and they reside on a networked drive. I setup the input to continuously monitor the directory. Splunk is not indexing the data. When I go into the splunkd log I see the following:

WARN FilesystemChangeWatcher - error reading directory "\\Server\inetpub\logs\LogFiles\W3SVC4": The operation completed successfully.

Any ideas on what I have done wrong or what other steps I need to take to get the data to index? Do I need to add entries into local .conf files? When I was building the dashboards I moved some of the log files locally to the splunk system and indexed them, the logs indexed with no issues. Any advice is welcomed.

Tags (3)
0 Karma

lguinn2
Legend

Does the account that is running Splunk have the domain-level access that is necessary to read directories on a network drive?

lguinn2
Legend

That is good - but what user are you signed in as? What user credentials does the Splunk service use?

0 Karma

Bliide
Path Finder

I can view the logs across the network while remoted into the system with the Splunk installation.

0 Karma
Get Updates on the Splunk Community!

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...