Getting Data In

To monitor a Folder in Windows Server ?

chimbudp
Contributor

I need to monitor the Assembly folder in Windows Server :
[monitor://C:\Windows\assembly]
index=Assembly_monitor

the above stanza forwards no data into Splunk indexer.

i have set the source type as assembly and modified as below inputs.conf:

[monitor://C:\Windows\assembly]
index=Assembly_monitor
sourcetype=Assembly

& also edited props.conf as :

[Assembly]
NO_BINARY_CHECK = true

-- Even also i am not getting any data 😞
Please help

Tags (2)
0 Karma

arvidn
New Member

Hi, I think you are missing "\" before Windowsassembly

[monitor://C:\Windowsassembly]

0 Karma

chimbudp
Contributor

Yes. it was not displayed in question & ur answer too.
But i am using backslash wherever it required

0 Karma

arvidn
New Member

Should be "backslash" in front of Windowsassembly. But not shown in my answere, probably missing in question too?

0 Karma

Ayn
Legend
  • Do you see other data from this forwarder in your indexer?
  • Have you checked splunkd.log on the forwarder?
  • Did you have a look at the status of file inputs (http://blogs.splunk.com/2011/01/02/did-i-miss-christmas-2/)?
  • Most of all, why would you want to index the binary data in the assembly directory? What are you trying to achieve?
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...