Getting Data In

Text File Ingestion

sswigart
Engager

I want Splunk to ingest my AV log. I made the following entry in the inputs.conf file:
Note: The log file is a text file with no formatting.

[monitor://C:ProgramData\'Endpoint Security'\logs\OnDemandScan_Activity.log]

disable=0
index=winlogs
sourcetype=WinEventLog:AntiVirus
start_from=0
current_only=0
checkpointInterval = 5
renderXml=false

 

My question is:

Is the stanza written correctly?

When I do a search I am not seeing anything.

Labels (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Try removing the quotes from the file path.

Check splunkd.log for errors relating to that input.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

[Coming Soon] Splunk Observability Cloud - Enhanced navigation with a modern look and ...

We are excited to introduce our enhanced UI that brings together AppDynamics and Splunk Observability. This is ...