Monitoring Splunk

Indexing Sharepoint mounted path in Splunk?

PraveenaR
Explorer

I am able to index my local C:/ drive local files in Splunk , but unable to index X:/ drive (Sharepoint path) folder data through inputs.conf.

Note:

X:/ drive contains the mounted path of Sharepoint location

Any help would be appreciated!

Thanks,
Praveena

 

 

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

What happens when you try to index the X: drive?  What error(s) do you get?

Is Splunk running as a user with access to that drive?  See https://docs.splunk.com/Documentation/Splunk/9.0.1/Data/ConsiderationsfordecidinghowtomonitorWindows...

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

What happens when you try to index the X: drive?  What error(s) do you get?

Is Splunk running as a user with access to that drive?  See https://docs.splunk.com/Documentation/Splunk/9.0.1/Data/ConsiderationsfordecidinghowtomonitorWindows...

---
If this reply helps you, Karma would be appreciated.

PraveenaR
Explorer

@richgalloway , Thanks for the support!!

I found the issue for not reading the file from the sharepoint,

It is due to the access error (as you mentioned) in reading the file in sharepoint from Splunk.

I tried enabling the debug logs and found it.

PraveenaR
Explorer

Splunk has Domain Account. 
Note:
My X: drive data are not reflecting in splunk web. (No Errors)

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's surprising that Splunk would not index any data and not report anything about it.  Did you check splunkd.log?  What is the inputs.conf stanza for the X drive?

---
If this reply helps you, Karma would be appreciated.

PraveenaR
Explorer

Monitoring Stanza:

[monitor://X:\ASERENS\ENX\ENX1\200_Licensing\100_SparxSystems-EA\OrderingLicsMaint\2021\*.txt]

Yeah, I checked the log as well, but couldn't find any errors.


0 Karma

richgalloway
SplunkTrust
SplunkTrust

Where is the rest of the stanza?  I expected to see more than the heading.

What query are you using to find the events from the X: drive?

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...