Getting Data In

Need input stanza for a shared drive

anandhalagarasa
Path Finder

Hi Team,

I have a following path which is located in a shared drive so how should i need to write the inputs.conf (monitor stanza)..

i.e
index=xyz
sourcetype=abc

So the full path for the log file folder would be:

M:\Local\orex\keen\Archive\Error_Path\

Here Local folder is a shared drive in between. So kindly help to provide the inputs.conf for the file.

0 Karma

harsmarvania57
Ultra Champion

Hi,

Have you tried M:\Local\orex\keen\Archive\Error_Path\ in monitor stanza in inputs.conf ? If yes then is it not working ?

0 Karma

anandhalagarasa
Path Finder

I have already tried the way which you have suggested but still logs were not getting ingested into Splunk. And also currently I have tried this one as well. Since the folder "Local" is a shared one but still its not working.

[monitor://\M:\Local\orex\keen\Archive\Error_Path]

Hence kindly help

0 Karma

harsmarvania57
Ultra Champion

Ok, I never tried this before but can you please run net use on command prompt on windows server and try to use Remote path in your monitor stanza ?

Have a look at comment by gkanapathy on https://answers.splunk.com/answers/1730/windows-mapped-drive-and-light-forwarding.html

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...