Getting Data In

inputs.conf and Windows path

tlmayes
Contributor

I know this should be simple, but for whatever reason, it's not working

Have a production Windows 2012 server where we are collecting application logs from a log file. The path is
C:\Program Files\somepath..... so created an inputs.conf as follows

[monitor://C:\Program Files\somepath\]
index=someindex
sourcetype=somesourcetype
whitelist=\logfile.*$

Restarted the Windows UF service, no errors, but no events either (yes, confirmed there are events). So suspected permissions, and instead used:

    [monitor://C:\Test Folder\somepath\]
    index=someindex
    sourcetype=somesourcetype
    whitelist=\logfile.*$

Again, nothing, so used:

    [monitor://C:\TestFolder\somepath\]
    index=someindex
    sourcetype=somesourcetype
    whitelist=\logfile.*$

Without the whitespace, and works as expected. Put the whitespace back in, modified the log file so as to force collection, and again nothing. Was able to reproduce all on a 2012 test server. There is no provision I am aware of in inputs.conf to account for whitespace since it is supposed to be automatically recognized. What am I missing?

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi tlmayes,
did you already tried?

[monitor://C:\Program Files\somepath\logfile.*]
index=someindex
sourcetype=somesourcetype

Bye.
Giuseppe

View solution in original post

tlmayes
Contributor

Sometimes it is the simple things... Removing the recursive line fixed it

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi tlmayes,
did you already tried?

[monitor://C:\Program Files\somepath\logfile.*]
index=someindex
sourcetype=somesourcetype

Bye.
Giuseppe

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...