Getting Data In

Why am I not able to ingest logs from a NAS mapped drive?

csharm21
Loves-to-Learn

Hi all,

I am trying to ingest data from a Windows server from one mapped NAS drive. But i am not able to do it due to the below reason.

  1. First i mapped the NAS drive on the Windows machine but the Splunk forwarder is not able to see the drive.
  2. Then i also tried using the UNC path, but in this case, Splunk is trying to read the NAS files but it give "Permission denied issue"
  3. I also tried creating shortcut of NAS drive. In this case, also Splunk forwarder is able to read the file system but says "Permission denied issue". Can anyone help me to fix this?

Thanks in advance.

Tags (1)
0 Karma

schose
Builder

Hi,

mapped windows drives are user specific. When spunkforwarder should access logs from a mapped drive, the drive have to be mapped in the user context where UF is running.

Permissions denied may indicate, that your UF is running as system user. In that case the COMPUTERNAME$ account have to be used to grant access rights.

0 Karma

csharm21
Loves-to-Learn

Thanks for the response. I not that good in windows could you please help me to uderstand " COMPUTERNAME$ account have to be used to grant access rights" who can we grant this access

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...