Getting Data In

universal forwarder cannot find the path which I want to specify

p1004
New Member

When I install the universal forwarder on my DHCP server, I want to monitor the DHCP folder under system32, but from the software, when I use "path to monitor", I cannot find the DHCP folder through Directory, can you let me know why?

Tags (2)
0 Karma

Runals
Motivator

You using the case sensitive path to your logs? Since you haven't posted the path to your own and you mention system32 I'm guessing the path is the default one. This has worked for me.

[monitor://C:\WINDOWS\system32\dhcp]
sourcetype = DhcpSrvLog
crcSalt = <SOURCE>
disabled = false
whitelist = Dhcp.+\.log

p1004
New Member

Thanks for your answer, I am running a domain admin account, and it is in the local admin group, the permission should not be a problem.

0 Karma

ShaneNewman
Motivator

Is Splunk setup to run as a system account or a domain account? If it is setup as a domain account, it may not have the correct permissions to that directory.

0 Karma

ShaneNewman
Motivator

If you browse the folder directory as the domain account on the server itself, can you see the files you want to monitor?

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...