Getting Data In

Why am I not able to ingest logs from a NAS mapped drive?

csharm21
Loves-to-Learn

Hi all,

I am trying to ingest data from a Windows server from one mapped NAS drive. But i am not able to do it due to the below reason.

  1. First i mapped the NAS drive on the Windows machine but the Splunk forwarder is not able to see the drive.
  2. Then i also tried using the UNC path, but in this case, Splunk is trying to read the NAS files but it give "Permission denied issue"
  3. I also tried creating shortcut of NAS drive. In this case, also Splunk forwarder is able to read the file system but says "Permission denied issue". Can anyone help me to fix this?

Thanks in advance.

Tags (1)
0 Karma

schose
Builder

Hi,

mapped windows drives are user specific. When spunkforwarder should access logs from a mapped drive, the drive have to be mapped in the user context where UF is running.

Permissions denied may indicate, that your UF is running as system user. In that case the COMPUTERNAME$ account have to be used to grant access rights.

0 Karma

csharm21
Loves-to-Learn

Thanks for the response. I not that good in windows could you please help me to uderstand " COMPUTERNAME$ account have to be used to grant access rights" who can we grant this access

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...