Getting Data In

To monitor a Folder in Windows Server ?

chimbudp
Contributor

I need to monitor the Assembly folder in Windows Server :
[monitor://C:\Windows\assembly]
index=Assembly_monitor

the above stanza forwards no data into Splunk indexer.

i have set the source type as assembly and modified as below inputs.conf:

[monitor://C:\Windows\assembly]
index=Assembly_monitor
sourcetype=Assembly

& also edited props.conf as :

[Assembly]
NO_BINARY_CHECK = true

-- Even also i am not getting any data 😞
Please help

Tags (2)
0 Karma

arvidn
New Member

Hi, I think you are missing "\" before Windowsassembly

[monitor://C:\Windowsassembly]

0 Karma

chimbudp
Contributor

Yes. it was not displayed in question & ur answer too.
But i am using backslash wherever it required

0 Karma

arvidn
New Member

Should be "backslash" in front of Windowsassembly. But not shown in my answere, probably missing in question too?

0 Karma

Ayn
Legend
  • Do you see other data from this forwarder in your indexer?
  • Have you checked splunkd.log on the forwarder?
  • Did you have a look at the status of file inputs (http://blogs.splunk.com/2011/01/02/did-i-miss-christmas-2/)?
  • Most of all, why would you want to index the binary data in the assembly directory? What are you trying to achieve?
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...