Getting Data In

splunk universal forwarder not pullng custom logs.

suryaaruna
New Member

Team,

I am having some windows servers which am able to get windows event logs, perfmons but the custom logs am not able to pull the same.

here is my inputs.conf configuration. i have checked the case sensitivity too as we got one situation wherein correction of case sensitivity didfix the issue. But in this case none is working for me.

[monitor:///D:\logfiles\ARBGlobal\SalesCoreApp\SaleCoreApp.log]
sourcetype = salescore
disabled = 0
ignoreOlderThan=7d

Request your help in fixing the issue.

Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi òsuryaaruna,
you have to use only two slashes before path, not three, three is for Unix:

[monitor://D:\logfiles\ARBGlobal\SalesCoreApp\SaleCoreApp.log]

Ciao.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi òsuryaaruna,
you have to use only two slashes before path, not three, three is for Unix:

[monitor://D:\logfiles\ARBGlobal\SalesCoreApp\SaleCoreApp.log]

Ciao.
Giuseppe

0 Karma

suryaaruna
New Member

oh yes. thanks. it is two slashes. Thanks for your help.

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...