Getting Data In

Why am I not able to ingest logs from a NAS mapped drive?

csharm21
Loves-to-Learn

Hi all,

I am trying to ingest data from a Windows server from one mapped NAS drive. But i am not able to do it due to the below reason.

  1. First i mapped the NAS drive on the Windows machine but the Splunk forwarder is not able to see the drive.
  2. Then i also tried using the UNC path, but in this case, Splunk is trying to read the NAS files but it give "Permission denied issue"
  3. I also tried creating shortcut of NAS drive. In this case, also Splunk forwarder is able to read the file system but says "Permission denied issue". Can anyone help me to fix this?

Thanks in advance.

Tags (1)
0 Karma

schose
Builder

Hi,

mapped windows drives are user specific. When spunkforwarder should access logs from a mapped drive, the drive have to be mapped in the user context where UF is running.

Permissions denied may indicate, that your UF is running as system user. In that case the COMPUTERNAME$ account have to be used to grant access rights.

0 Karma

csharm21
Loves-to-Learn

Thanks for the response. I not that good in windows could you please help me to uderstand " COMPUTERNAME$ account have to be used to grant access rights" who can we grant this access

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...