Getting Data In

Windows log file data is not coming

sekhar463
Path Finder

hai 

i have configured below log file stanza but not getting data into splunk from windows UF

having latest on Jan 4th but those data also not came 
is any parameter need to add ?

below is the config file 

[monitorNoHandle://C:\Program Files\Crestron\CCS400\User\Logs\CCSFirmwareUpdate.txt]
index=Testindx
sourcetype=test_sourcetype
disabled=0

Labels (3)
0 Karma

dural_yyz
Communicator

https://docs.splunk.com/Documentation/Splunk/9.1.2/Admin/Inputsconf

[MonitorNoHandle://<path>]

* This input intercepts file writes to the specific file.

It appears this monitor config does not read the file itself but only intercepts what is about to be written to the file.  Your image shows last modified as Jan 4th which is your stated last ingest.

I think your configuration will only capture future content and not existing content. 

0 Karma

sekhar463
Path Finder

still not coming 

the file is text file as below and its under Program Files\Crestron\CCS400\User\Logs\

and want to ingest the file CCSFirmwareUpdate.txt

sekhar463_0-1705673163212.png

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sekhar463 ,

which user are you using to run Splunk, has this user the grants to read this file?

please check that the path of the file is correct, runing the dir command in a cmd window.

Ciao.

Giuseppe

0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. Do you get _any_ data from this forwarder? Especially events into _internal index.

2. Do you see any errors in c:\program files\splunk (or SplunkUniversalForwarder, depending on version)\var\log\splunk\splunkd.log on the forwarder?

3. What is the output of

splunk list monitor

and

splunk list inputstatus

run on your UF?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sekhar463,

I suppose that you already configured outputs.conf and that you're already reeving logs from that machine.

Please try this:

[monitor://C:\Program Files\Crestron\CCS400\User\Logs\CCSFirmwareUpdate.txt]
index=Testindx
sourcetype=test_sourcetype
disabled=0

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...