Getting Data In

Universal Forwarder and folder monitoring

gdavid
Path Finder

I installed a universal forwarder on my workstation to test monitoring some server directories for changes.
during the install i selected monitored c:\mytestfolder
i see events coming into my index but i can't find which inputs.conf file on my workstation it's specified in.

also for some reason the events come in like this.
WARN FileClassifierManager - The file 'C:\MyTestFolder\Tulips.jpg' is invalid. Reason: binary
INFO TailingProcessor - Ignoring file 'C:\MyTestFolder\Tulips.jpg' due to: binary

Tags (1)
0 Karma

gdavid
Path Finder

finally found it. it seems that settings that come in during the install are located in
C:/Program Files/SplunkUniversalForwarder/etc/apps/MSICreated/local

0 Karma

gdavid
Path Finder

no local folder under [etc/apps/search/]
the default folder has an empty inputs.conf

i may be using the wrong monitor. i want to see file/directory changes, not parse the files.
but until i can find where monitor is specified i cant change it.

0 Karma

Kate_Lawrence-G
Contributor

I believe in the windows version the inputs.conf is located under the etc/apps/search/local directory.
You also should probably exclude the JPG files in that inputs.conf file as it is binary and will throw that type of message in the splunkd.log (/var/log/splunk/splunkd.log)

Thanks,

Kate

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...