Getting Data In

UNC Path with $ sign

peter_gianusso
Communicator

We have an UNC name in the inputs.conf

monitor://\njros1bva0597\d$\LogFiles\W3SVC1\*.log

I suspect our share, d$, is the problem as to why this is not working. When it gets converted to regex, I think $ is a special character in regex.

Any suggestions? We can't change the Windows share name.

Tags (3)
0 Karma
1 Solution

peter_gianusso
Communicator

Splunk does not like the d$ in the UNC path. It can't handle it. Must be an inputs.conf and props.conf approach.

inputs.conf
[monitor://\njros1bva0597d$LogFilesW3SVC1]
disabled = 0
host = NJROS1BVA0621ABC
index=imaging
whitelist = .log$

Props.conf
[source::...\CAPPM*.log] sourcetype = SOURCE1

View solution in original post

peter_gianusso
Communicator

Splunk does not like the d$ in the UNC path. It can't handle it. Must be an inputs.conf and props.conf approach.

inputs.conf
[monitor://\njros1bva0597d$LogFilesW3SVC1]
disabled = 0
host = NJROS1BVA0621ABC
index=imaging
whitelist = .log$

Props.conf
[source::...\CAPPM*.log] sourcetype = SOURCE1

bwooden
Splunk Employee
Splunk Employee

Monitor statements proper support wildcard matching (*) and recursive directory matching (...). Regular expressions can be used as monitor options, for whiltelist and blacklist as an example, but the dollar sign shouldn't be causing problems here.

Is Splunk running as a local system account or as a domain account with network privileges? If it is running as a local system account it may not be able to access network shares. If that is the case the service will need to be configured to run as a service account with access to the network path.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...