Monitoring Splunk

File monitoring windows to linux

mjlsnombrado
Communicator

Hi, I have a Windows machine as a Universal forwarder which forwards data to Splunk instance on a Linux box. I want the csv file on the windows forwarder to be monitored on Splunk. It is showing on the forwarded inputs but its not getting indexed on the Splunk instance.

inputs.conf
[monitor://C:\Users\mjsn\Desktop\linuxToWindowsTest\mgmt_test.csv]
disabled = false
index = vm_test_app_idx
sourcetype= st_vm_test_app

outputs.conf
[tcpout]
defaultGroup = monitor_test

[tcpout:monitor_test]
server = 10.5.2.77:9997

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check your default index. Also, try searching "the future" in case timestamps are off. That is, set latest=+24h in your query.

---
If this reply helps you, Karma would be appreciated.
0 Karma

ansif
Motivator

Check if index is defined in the Indexer? if other monitor are working from the UF then ports are fine.

check the internal log with mgmt_test.csv ,that will tell you some clue why it is dropping at indexer.

bojanisch
Path Finder

I assume these configs are on the UF. Have you defined the index on your Linux box? Also have you enabled the port listening on the indexer? And is the IP reachable from the UF?

mjlsnombrado
Communicator

Yes, I enabled the port on the indexer, also the IP is reachable from the UF

0 Karma

bojanisch
Path Finder

Any errors visible in your _internal logs on your indexer? Maybe permission issues? Note that Splunks config are case sensitive, maybe a mistyping in your path?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...