Getting Data In

Why am I receiving this error: Skipping itemPath, does not match path....

ehowardl3
Path Finder

I've recently been running into issues with Splunk not ingesting files, both on universal and heavy forwarders. The example here is a UF on a Windows server. In this example, I'm trying to ingest \\path\to\file.csv, and the error I get is:

DEBUG TailingProcessor - Skipping itemPath='E:\path\to\some\other\file.txt, does not match path='\\path\to\file.csv' :Not a directory :Not a symlink

My input looks like:

[monitor://\\\\path\to\file.csv]
index = myindex
sourcetype = mysourcetype
initCrcLength = 512

Also, I had to turn on debug logging in log.cfg to even see these errors. Otherwise there were no errors at all.

Any ideas?

Thanks

edoardo_vicendo
Builder

Same here, the UF was working fine on a Windows server than suddenly started to not ingest the file anymore. To see the error I had to put in debug mode the universal forwarder. The strange thing is that other files are still monitored and forwarded correctly.

I have even added followSymlink=false and CHECK_METHOD=modtime without any luck

#inputs.conf
[monitor://D:\path\to_*\file-*_*.csv]
disabled=0 index=myindex sourcetype=mysourcetype crcSalt = <SOURCE>
followSymlink=false
#props.conf
[source::D:\path\to_*\file-*_*.csv] CHECK_METHOD=modtime

 

0 Karma

EUgalder
New Member

I have the same issue. 
Somebody know how to fix this?? 

0 Karma

timrich66
Communicator

Hi, I am getting the same error on a unix box.  Did you ever come to a conclusion?  The input works fine for exactly the same path on a different server.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...