Getting Data In

Why is my universal forwarder on Windows server 2012 R2 not collecting log files with my attempted configurations?

lisaac
Path Finder

I have a monitor that that isn't working. I turned debug on in log.cfg, and the Universal Forwarder reports no match on whitelist. The following has been tried:

[monitor://E:\Program Files\Microsoft SQL Server\MSRS11.MSSQLSERVER\Reporting Services\LogFiles] 
disabled = false 
index = app_ops_prod 
whitelist=ReportServerService*.log 
sourcetype = mssql:ilink:rptsvrsvc 
ignoreOlderThan = 3d 

OR

[monitor://E:\Program Files\Microsoft SQL Server\MSRS11.MSSQLSERVER\Reporting Services\LogFiles\ReportServerService*.log] 
disabled = false 
index = app_ops_prod 
sourcetype = mssql:ilink:rptsvrsvc 
ignoreOlderThan = 3d 

Splunkd.log says that is matches and then skips. As noted above, I tried 2 configurations.

04-07-2016 17:34:20.348 +0000 DEBUG TailingProcessor - Item '' matches stanza: /E:\Program Files\Microsoft SQL Server\MSRS11.MSSQLSERVER\Reporting Services\LogFiles. 
04-07-2016 17:34:20.348 +0000 DEBUG TailingProcessor - Not using stanza for this item (File did not match whitelist 'ReportServerService*.log'.). 

The file is E:\Program Files\Microsoft SQL Server\MSRS11.MSSQLSERVER\Reporting Services\LogFiles\ReportServerService__test.log. The host is Windows Server 2012 r2, and the UF is at verison 6.2.6.

0 Karma

somesoni2
Revered Legend

Give this a try

[monitor://E:\Program Files\Microsoft SQL Server\MSRS11.MSSQLSERVER\Reporting Services\LogFiles\] 
disabled = false 
index = app_ops_prod 
whitelist=ReportServerService.*\.log$
sourcetype = mssql:ilink:rptsvrsvc 
ignoreOlderThan = 3d 
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...