Getting Data In

Why am I not able to ingest logs from a NAS mapped drive?

csharm21
Loves-to-Learn

Hi all,

I am trying to ingest data from a Windows server from one mapped NAS drive. But i am not able to do it due to the below reason.

  1. First i mapped the NAS drive on the Windows machine but the Splunk forwarder is not able to see the drive.
  2. Then i also tried using the UNC path, but in this case, Splunk is trying to read the NAS files but it give "Permission denied issue"
  3. I also tried creating shortcut of NAS drive. In this case, also Splunk forwarder is able to read the file system but says "Permission denied issue". Can anyone help me to fix this?

Thanks in advance.

Tags (1)
0 Karma

schose
Builder

Hi,

mapped windows drives are user specific. When spunkforwarder should access logs from a mapped drive, the drive have to be mapped in the user context where UF is running.

Permissions denied may indicate, that your UF is running as system user. In that case the COMPUTERNAME$ account have to be used to grant access rights.

0 Karma

csharm21
Loves-to-Learn

Thanks for the response. I not that good in windows could you please help me to uderstand " COMPUTERNAME$ account have to be used to grant access rights" who can we grant this access

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...