Getting Data In

When i check logfile and found process cannot access the file because it is being.Is there any solution for this?

ravivasant
Engager

WARN FilesystemChangeWatcher - error getting attributes of path "C:\pagefile.sys": The process cannot access the file because it is being used by another process.

Labels (1)

Richfez
SplunkTrust
SplunkTrust

I stumbled across this while trying to find a solution to some UFs that have gone haywire and decided to try to monitor a bunch of files exactly like pagefile.sys, which of course is silly and doesn't work.

btool says nothing's *told* it to try to monitor those.

I'm going to have them try to restart one of the affected UFs; something's going on and I'll update here when I find out what in case others stumble across this problem.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Notoce that this is  not a monitor input. This is from a fschange input. While - if we are to believe the conf spec file - this input type has been deprecated since Splunk 5 (sic!) modern Splunk still comes with at least one fschange input on $SPLUNK_HOME defined by default.

Have you checked your config for any other fschange inputs? 

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

What do you expect to do with pagefile.sys in Splunk? That's the OS swap file, probably locked exclusively and hence not accessible by any other process. Plus, it is a binary file and thus not really suitable for ingestion into Splunk.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...