Getting Data In

When i check logfile and found process cannot access the file because it is being.Is there any solution for this?

ravivasant
Engager

WARN FilesystemChangeWatcher - error getting attributes of path "C:\pagefile.sys": The process cannot access the file because it is being used by another process.

Labels (1)

Richfez
SplunkTrust
SplunkTrust

I stumbled across this while trying to find a solution to some UFs that have gone haywire and decided to try to monitor a bunch of files exactly like pagefile.sys, which of course is silly and doesn't work.

btool says nothing's *told* it to try to monitor those.

I'm going to have them try to restart one of the affected UFs; something's going on and I'll update here when I find out what in case others stumble across this problem.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Notoce that this is  not a monitor input. This is from a fschange input. While - if we are to believe the conf spec file - this input type has been deprecated since Splunk 5 (sic!) modern Splunk still comes with at least one fschange input on $SPLUNK_HOME defined by default.

Have you checked your config for any other fschange inputs? 

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

What do you expect to do with pagefile.sys in Splunk? That's the OS swap file, probably locked exclusively and hence not accessible by any other process. Plus, it is a binary file and thus not really suitable for ingestion into Splunk.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...