Getting Data In

SplunkUniversalForwarder not forwarding input files

anantshah
Path Finder

We are using SplunkUniversalForwarder 4.2.3 x64 to forward some logs. inputs.conf has the following stanzas

[monitor://D:\Program Files (x86)\MicroStrategy\Web Logs\CustomMSTRLog*]
disabled = 0
sourcetype = stg_mstr_esm_log
crcSalt =

[WinEventLog:Application]
disabled = 0

[WinEventLog:System]
disabled = 0

Eventlogs are getting forwarded without any issues but the apache logs are not. I am not seeing any errors in splunkd.log on the forwarder.

0 Karma
1 Solution

anantshah
Path Finder

I was able to resolve the issue using a whitelist. I think the wild card does not work because (x86) in the path.

[monitor://D:\Program Files (x86)\MicroStrategy\Web Logs]
whitelist = Custom[^/]*.log$
disabled = 0
sourcetype = stg_mstr_esm_log
crcSalt =

View solution in original post

0 Karma

anantshah
Path Finder

I was able to resolve the issue using a whitelist. I think the wild card does not work because (x86) in the path.

[monitor://D:\Program Files (x86)\MicroStrategy\Web Logs]
whitelist = Custom[^/]*.log$
disabled = 0
sourcetype = stg_mstr_esm_log
crcSalt =

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi anaptshah

there are many things, that could prevent a file from being read by the universal forwarder:

  • file permission: does the user/service account which runs the splunkd have read access to this file?
  • typo in the stanza: does splunkd.exe list monitor show your stanza with the correct path?
  • maybe the file just does not get changed?
  • did you restart your universal forwarder? it happened to me sometimes, that after the restart the file gets immediately read by splunk

hope this helps a bit and you get it fixed.

cheers

anantshah
Path Finder

I uploaded the incorrect stanza, the stanza thats not working is as follows

[monitor://D:\Program Files (x86)\MicroStrategy\Web Logs\CustomMSTRLog*]
disabled = 0
sourcetype = stg_mstr_esm_log
crcSalt =

splunkd.exe list monitor shows the directory but does not show any of the files. Is there something special about (x86)? The stanza on the original post works fine.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mile High Learning with Splunk University, Denver, Colorado

If Denver is known for its mile-high elevation, Splunk University is about to raise the bar on technical ...

IT Service Intelligence 5.0 Series: Your Guide to the June Launch

We are excited to announce the June release of Splunk IT Service Intelligence (ITSI) 5.0. This update ...

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...