Splunk Search

How do you monitor a Windows shared directory?

alonsocaio
Contributor

I have Splunk Enterprise installed on a Linux Server. I need to monitor a Windows Shared Directory containing a CSV file that needs to be uploaded daily to Splunk.

Each time I try to create a monitor (Add Data -> Monitor -> Files & Directories) I get this error: "Parameter Name: Path must be absolute".

Is there any way to fix that? How can I check if the Splunk has access to the Windows shared directory?

0 Karma
1 Solution

efavreau
Motivator

Look to see if you can mount the windows directory. If the windows directory looks like part of the Linux filesystem, and Splunk has the permissions to access the mount, it may work for you.

###

If this reply helps you, an upvote would be appreciated.

View solution in original post

efavreau
Motivator

Look to see if you can mount the windows directory. If the windows directory looks like part of the Linux filesystem, and Splunk has the permissions to access the mount, it may work for you.

###

If this reply helps you, an upvote would be appreciated.

alonsocaio
Contributor

I mounted the directory using cifs-utils. It worked now. Thanks.

0 Karma

efavreau
Motivator

Glad it worked for you. I'll write up a short answer.

###

If this reply helps you, an upvote would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Install the Splunk Universal Forwarder on a Windows system that has access to the shared directory and configure it to monitor the file.

---
If this reply helps you, Karma would be appreciated.

joesrepsolc
Communicator

This is difficult to do given a windows share sits on a VIP and is load balanced. So this is not as straight forward as it may seem.

0 Karma

efavreau
Motivator

Can you mount the windows directory?

###

If this reply helps you, an upvote would be appreciated.
0 Karma

alonsocaio
Contributor

I cannot mount the Windows directory in the Linux server that Splunk is installed.

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...