Getting Data In

Splunk (8.1.2 and previous) not reading data from all stanzas

madingdisk
Explorer

Dear community,

I have a massive issue with a (single hosted) Splunk installation reading files from a local drive/ UNC paths: Splunk does not read these files and doesn't show them as "available" in the Files & directories config page:

 

1.PNG

The splunkd service which is running on WIndows 2016 is configured with a local administrator user who has also full permissions on the local drives/ permissions on the UNC paths. I have checked the access logging on with this technical user to the machine and opening the paths.

There is also no Virus Scanner blocking Splunk (verified with procmon). The stanzas look as follows (and have always worked for other customers and for this one some time ago):

madingdisk_0-1615474045568.png

and

madingdisk_1-1615474108751.png

I searched through the logs but couldn't find something really useful. The log states no issue with the file watch:

madingdisk_2-1615474210072.png

Since I'm really desperate, I also tried adding the following without success:

- crcSalt = <SOURCE>

- alwaysOpenFile = 1

Any ideas? Would be much appreciated. If I can't resolve it like this, I will have to try reinstalling spunk from scratch moving the configuration to the vanilla installation to see if it works in the new installation.

thanks

mading

 

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...