Getting Data In

When i check logfile and found process cannot access the file because it is being.Is there any solution for this?

ravivasant
Engager

WARN FilesystemChangeWatcher - error getting attributes of path "C:\pagefile.sys": The process cannot access the file because it is being used by another process.

Labels (1)

Richfez
SplunkTrust
SplunkTrust

I stumbled across this while trying to find a solution to some UFs that have gone haywire and decided to try to monitor a bunch of files exactly like pagefile.sys, which of course is silly and doesn't work.

btool says nothing's *told* it to try to monitor those.

I'm going to have them try to restart one of the affected UFs; something's going on and I'll update here when I find out what in case others stumble across this problem.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Notoce that this is  not a monitor input. This is from a fschange input. While - if we are to believe the conf spec file - this input type has been deprecated since Splunk 5 (sic!) modern Splunk still comes with at least one fschange input on $SPLUNK_HOME defined by default.

Have you checked your config for any other fschange inputs? 

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

What do you expect to do with pagefile.sys in Splunk? That's the OS swap file, probably locked exclusively and hence not accessible by any other process. Plus, it is a binary file and thus not really suitable for ingestion into Splunk.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...