As the title says.
Forwarder File Monitor stopped working at 23:59 June 30th 2013
inputs.conf:
[monitor://E:\Logs]
disabled = 0
sourcetype = mftlogs
[WinEventLog:Security]
disabled = 0
Debug:
07-01-2013 13:51:05.570 +0200 DEBUG TcpOutputProc - Registering Channel for : source::E:\Logs<removed>.log|host::MFTD|mftlogs| :9997, oneTimeClient=0, _events.size()=0, _refCount=1, _waitingAckQ.size()=0, _supportsACK=0
07-01-2013 13:51:05.570 +0200 DEBUG TcpOutputProc - Unregistering Channel for : source::E:\Logs<removed>.log.log|host::MFTD|mftlogs| :9997, oneTimeClient=0, _events.size()=1, _refCount=2, _waitingAckQ.size()=0, _supportsACK=0
Windows Eventlog still gets inserted into splunk, but not the logs.
Anyone ? 😞
... View more