Getting Data In

Why am I getting error "Parameter name: Path must be absolute" trying to enable network file share monitoring using Splunk 6.2.2 installed on Linux?

mmohiuddin
Path Finder

Hi

I am unable to enable monitoring on a network file share, \servername\f$\XXX\XXX on a linux server. I am adding the path as data inputs from the GUI. I had made sure that the Splunkd is running as root on the linux splunk search head server. I am getting the following error:

Parameter name: Path must be absolute.

I was able to test the same thing out on my Windows Search Head on version 6.1.4 version and splunkd started monitoring files from the network file share \servername\f$\XXX\XXX, but when I am trying to replicate the same thing on linux Splunk Search Head server, I get the parameter name : path must be absolute error.

Please guide me if I am missing something.

Tags (4)

jkat54
SplunkTrust
SplunkTrust

The syntax for monitoring a network share is different between windows and linux:

from http://docs.splunk.com/Documentation/Splunk/6.3.0/Data/MonitorfilesanddirectorieswithSplunkWeb#Selec... :

To monitor a shared network drive, enter the following: <myhost>/<mypath> (or \\<myhost>\<mypath> on Windows). Make sure Splunk has read access to the mounted drive, as well as to the files you wish to monitor.

You may also prefer to "mount" the network drive on the linux box before monitoring it so that it will be on a local path like /mnt/networkShare

Finally, make sure the user splunkd is running as has permission on the network share.

https://answers.splunk.com/answers/6020/monitoring-a-remote-server-directory-from-my-workstation.htm...

0 Karma

MuS
Legend

Hi mmohiuddin,

can you provide the complete monitor stanza?
Usually this kind of error pops up if you try to monitor a windows path from linux like this:

[monitor://c:\foo\bar\file.txt] 

Or on a windows server something like this:

[monitor:///foo/bar/file.txt]
0 Karma

napomokoetle
Communicator

Was getting the "ERROR AdminManager - Parameter name: Path must be absolute" problem when I tried upLoad File into Splunk. After a couple of attempt without success on Firefox web browser, I decided to try Chrome browser and the data file was uploaded successfully!!!

I hope that saves someone some grief!

0 Karma

sloshburch
Splunk Employee
Splunk Employee

Seeing the same thang while uploading csv from my local desktop. Interesting...

gbronner_rbc
Explorer

Happened to me as well. Went back and tried uploading it again using the saved format I'd created early, and did not get the error. Wondered if something happened on the filesystem, as the file was on a UNC path.

0 Karma

sloshburch
Splunk Employee
Splunk Employee

Worked when I selected the file (rather than drag and drop into UI).

0 Karma

tlagatta_splunk
Splunk Employee
Splunk Employee

@mmohiuddin, I encountered this same error last night when uploading some data. This morning, I tried uploading the data on a different network, and it worked without any problem. Were you able to resolve your issue?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...