My Splunk Universal Forwarder is not able to read the modification on a file under the path "C:\Program Files (x86)"
My inputs.conf is:
[monitor://C:\Program Files (x86)\TeamViewer\TeamViewer13_Logfile.log] sourcetype = TeamViewer:Connection:Client index = teamviewer disabled = 0 queue = indexQueue
What am I doing wrong? I cannot see anything about this file in splunkd.log.
@danielearangiomazza If your problem is resolved, please accept the answer to help future readers.
teamviewerindex in the indexer?