Getting Data In

Universal Forwarder on Windows not picking up log files?

Dmikos1271
Explorer

I've been able to deploy universal forwarders to dozens of Windows servers that run IIS logs. I have created a dedicated index and I have pushed an app (used to be Splunk supported, they have since moved to a different app package) to said forwarders. The forwarders are set to send the data to our indexer cluster. To cover my bases for the different versions I have included several different monitor stanzas in the inputs.conf file:

 

 

[monitor://C:\inetpub\logs\...\W3S*\*.log]

disabled = false

sourcetype = ms:iis:auto

index=iis



[monitor://C:\inetpub\logs\*\W3S*\*.log]

disabled = false

sourcetype = ms:iis:auto

index=iis



[monitor://C:\Program Files\Microsoft\Exchange Server\V*\Logging\Ews]

disabled = false

sourcetype = ms:iis:auto

index=iis

 

 

When deployed to the dozens of servers, I'm not seeing any data come back up or even any path watches coming back when searching the logs coming back from the universal forwarders. As a test I have added several files to a dedicated server and kept playing around with the monitor stanzas with no luck. When opening the inputs.conf locally on that server in notepad, the text looked merged so I added some spaces and line breaks. Restarted the service, I can path watches added but still nothing coming in. Even when specifying a path to a file, nothing comes in:

 

 

[monitor://C:\Test\logs\LogFiles\W3SVC1\u_ex221010.log]

disabled = false

sourcetype = ms:iis:auto

index=iis

 

 

For something that seems so simple, where am I going wrong?

Labels (3)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...