Our central Splunk server is Linux, running (now) the latest as I suspected there was a bug involved in this situation. I've deployed the Windows universal forwarder to a bunch of Windows Server 2008 machines, and due to a known bug in the installer (as shown to me by Splunk support) they had to be installed with no options, and configured after. Since there are a lot of machines, I'm attempting to automate everything.
Whenever I attempt to add in a monitor via the splunk command on our Linux server, I get an error. This is what it is:
splunk add monitor -uri https:// :8089 -auth
In handler 'monitor': Parameter name: Path does not exist.
It sounds like the monitor is only validated against what's valid for the local OS. Is this expected behavior or a bug? I've attempted the usual UNIX tricks -- encased the path in quotes, escaped the special characters, etc.
... View more