Hello,
In order to monitor a file via UF, those files should grant read-only permissions user and group as splunk:splunk on linux servers,
I have doubt on windows servers whether the user and group (splunk:splunk) is an active directory service account and group?
Thanks
Windows does not grant file access the same way that Linux does so instructions for Linux don't necessarily apply to Windows.
On any platform, the user running the UF needs read access to any files being monitored by the UF. On Windows, that's usually a local user, but can be a domain account.
Windows does not grant file access the same way that Linux does so instructions for Linux don't necessarily apply to Windows.
On any platform, the user running the UF needs read access to any files being monitored by the UF. On Windows, that's usually a local user, but can be a domain account.