Getting Data In

Problem with network logs

Bliide
Path Finder

I setup a data input from a network source. They are IIS logs and they reside on a networked drive. I setup the input to continuously monitor the directory. Splunk is not indexing the data. When I go into the splunkd log I see the following:

WARN FilesystemChangeWatcher - error reading directory "\\Server\inetpub\logs\LogFiles\W3SVC4": The operation completed successfully.

Any ideas on what I have done wrong or what other steps I need to take to get the data to index? Do I need to add entries into local .conf files? When I was building the dashboards I moved some of the log files locally to the splunk system and indexed them, the logs indexed with no issues. Any advice is welcomed.

Tags (3)
0 Karma

lguinn2
Legend

Does the account that is running Splunk have the domain-level access that is necessary to read directories on a network drive?

lguinn2
Legend

That is good - but what user are you signed in as? What user credentials does the Splunk service use?

0 Karma

Bliide
Path Finder

I can view the logs across the network while remoted into the system with the Splunk installation.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...