Splunk Enterprise

Can UF be installed in E drive and monitor logs present in different drive(Network drive)

Ashwini008
Builder

Hi,

I have installed Splunk UF in E drive on windows server and able to monitor all the logs present in E drive.

I have request to monitor Network drive logs present on the same windows server and the user has full access to network drive.

I have placed monitoring stanza under splunk_home/etc/system/local/inputs.conf( E drive) mentioning the path of the logs present in network drive . But i do not see any logs related to Network drive in Splunk.

Is there way to monitor network drive logs when UF is present in E drive on windows server?

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Did you restart the UF after editing inputs.conf (it's required)?

Check splunkd.log to see if the UF reports any problems reading E:.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 4

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...

GA: S3 Promote for Historical Data Ingestion in Splunk Cloud

Ingest Historical S3 Data On-Demand: Announcing the General Availability of S3 Promote We’re excited to share ...