Hello Team Splunk,
I am trying to add a monitor to a log file. When I do this as either the 'splunk' user or the 'root' user I receive the following error: "**Parameter name: Path is not readable.**" I noticed that as the 'splunk' user I cannot read the file with the *vi* program. However I can read the file as the root user. So why would I receive this error if the 'root' user can read the file and I am running the ./splunk program as 'root'. I also noticed that the log files I am trying to forward are on a network file system that is mounted on the operating system (OS). I am not sure if this mount makes a difference or not.
Also, I noticed I can add the entire directory but not the specific file I want to forward to the indexer. Also, when I monitor the entire directory the indexer only monitors some other out of date log file and not the log file I am after. 0_o I noticed that the files in this directory are executable except for the specific log file I am trying to monitor.
Regards,
rogue_carrot
↧