Getting Data In

Windows log file data is not coming

sekhar463
Path Finder

hai 

i have configured below log file stanza but not getting data into splunk from windows UF

having latest on Jan 4th but those data also not came 
is any parameter need to add ?

below is the config file 

[monitorNoHandle://C:\Program Files\Crestron\CCS400\User\Logs\CCSFirmwareUpdate.txt]
index=Testindx
sourcetype=test_sourcetype
disabled=0

Labels (3)
0 Karma

dural_yyz
Motivator

https://docs.splunk.com/Documentation/Splunk/9.1.2/Admin/Inputsconf

[MonitorNoHandle://<path>]

* This input intercepts file writes to the specific file.

It appears this monitor config does not read the file itself but only intercepts what is about to be written to the file.  Your image shows last modified as Jan 4th which is your stated last ingest.

I think your configuration will only capture future content and not existing content. 

0 Karma

sekhar463
Path Finder

still not coming 

the file is text file as below and its under Program Files\Crestron\CCS400\User\Logs\

and want to ingest the file CCSFirmwareUpdate.txt

sekhar463_0-1705673163212.png

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sekhar463 ,

which user are you using to run Splunk, has this user the grants to read this file?

please check that the path of the file is correct, runing the dir command in a cmd window.

Ciao.

Giuseppe

0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. Do you get _any_ data from this forwarder? Especially events into _internal index.

2. Do you see any errors in c:\program files\splunk (or SplunkUniversalForwarder, depending on version)\var\log\splunk\splunkd.log on the forwarder?

3. What is the output of

splunk list monitor

and

splunk list inputstatus

run on your UF?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sekhar463,

I suppose that you already configured outputs.conf and that you're already reeving logs from that machine.

Please try this:

[monitor://C:\Program Files\Crestron\CCS400\User\Logs\CCSFirmwareUpdate.txt]
index=Testindx
sourcetype=test_sourcetype
disabled=0

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...