Getting Data In

Why am I receiving this error: Skipping itemPath, does not match path....

ehowardl3
Path Finder

I've recently been running into issues with Splunk not ingesting files, both on universal and heavy forwarders. The example here is a UF on a Windows server. In this example, I'm trying to ingest \\path\to\file.csv, and the error I get is:

DEBUG TailingProcessor - Skipping itemPath='E:\path\to\some\other\file.txt, does not match path='\\path\to\file.csv' :Not a directory :Not a symlink

My input looks like:

[monitor://\\\\path\to\file.csv]
index = myindex
sourcetype = mysourcetype
initCrcLength = 512

Also, I had to turn on debug logging in log.cfg to even see these errors. Otherwise there were no errors at all.

Any ideas?

Thanks

edoardo_vicendo
Builder

Same here, the UF was working fine on a Windows server than suddenly started to not ingest the file anymore. To see the error I had to put in debug mode the universal forwarder. The strange thing is that other files are still monitored and forwarded correctly.

I have even added followSymlink=false and CHECK_METHOD=modtime without any luck

#inputs.conf
[monitor://D:\path\to_*\file-*_*.csv]
disabled=0 index=myindex sourcetype=mysourcetype crcSalt = <SOURCE>
followSymlink=false
#props.conf
[source::D:\path\to_*\file-*_*.csv] CHECK_METHOD=modtime

 

0 Karma

EUgalder
New Member

I have the same issue. 
Somebody know how to fix this?? 

0 Karma

timrich66
Communicator

Hi, I am getting the same error on a unix box.  Did you ever come to a conclusion?  The input works fine for exactly the same path on a different server.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...