Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

inputs.conf and Windows path

$
0
0
I know this should be simple, but for whatever reason, it's not working Have a production Windows 2012 server where we are collecting application logs from a log file. The path is C:\Program Files\somepath\..... so created an inputs.conf as follows [monitor://C:\Program Files\somepath\] index=someindex sourcetype=somesourcetype whitelist=\logfile.*$ Restarted the Windows UF service, no errors, but no events either (yes, confirmed there are events). So suspected permissions, and instead used: [monitor://C:\Test Folder\somepath\] index=someindex sourcetype=somesourcetype whitelist=\logfile.*$ Again, nothing, so used: [monitor://C:\TestFolder\somepath\] index=someindex sourcetype=somesourcetype whitelist=\logfile.*$ Without the whitespace, and works as expected. Put the whitespace back in, modified the log file so as to force collection, and again nothing. Was able to reproduce all on a 2012 test server. There is no provision I am aware of in inputs.conf to account for whitespace since it is supposed to be automatically recognized. What am I missing?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>