Getting Data In

fschange with \...\

mcbradford
Contributor

This is my inputs.conf

[fschange://C:\Users...\AppData\Local\Microsoft\Windows\Burn]
index=windows
recurse=true
sourcetype=opticalmediaburn
pollPeriod=60
followLinks=true
fullEvent=true
delayInMills=1000

I see this in my _internal log

FSChangeMonitor - Monitoring file or directory that doesn't exist at startup time - //C:\Users...\AppData\Local\Microsoft\Windows\Burn

What am I doing wrong. The file/path does exist

Tags (1)
0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee

You should be using [fschange:] not [fschange://]

Something like this:
[fschange:C:\Users\AppData\Local\Microsoft\Windows\Burn]

0 Karma

mcbradford
Contributor

I changed the syntax to:

[fschange:C:\Users...\AppData\Local\Microsoft\Windows\Burn]

and it is still not working.

Can you use ...\? There are lots of users, so we would not be able to specify a different path for each user.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...