Getting Data In

Splunk (8.1.2 and previous) not reading data from all stanzas

madingdisk
Explorer

Dear community,

I have a massive issue with a (single hosted) Splunk installation reading files from a local drive/ UNC paths: Splunk does not read these files and doesn't show them as "available" in the Files & directories config page:

 

1.PNG

The splunkd service which is running on WIndows 2016 is configured with a local administrator user who has also full permissions on the local drives/ permissions on the UNC paths. I have checked the access logging on with this technical user to the machine and opening the paths.

There is also no Virus Scanner blocking Splunk (verified with procmon). The stanzas look as follows (and have always worked for other customers and for this one some time ago):

madingdisk_0-1615474045568.png

and

madingdisk_1-1615474108751.png

I searched through the logs but couldn't find something really useful. The log states no issue with the file watch:

madingdisk_2-1615474210072.png

Since I'm really desperate, I also tried adding the following without success:

- crcSalt = <SOURCE>

- alwaysOpenFile = 1

Any ideas? Would be much appreciated. If I can't resolve it like this, I will have to try reinstalling spunk from scratch moving the configuration to the vanilla installation to see if it works in the new installation.

thanks

mading

 

Labels (1)
Tags (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...