Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How does monitor:// handle windows shortcuts to directories containing logs?

$
0
0
In an effort to get our inventory of inputs under control, I'm trying to get all servers to have one place for logs. Eg, `C:\LOGS`. When they want to add new files to monitor, they add a directory there, named after the sourcetype: `C:\LOGS\newsourcetype`. In that directory, they link (shortcut in the case of Windows) to the actual directory containing their logs. So `C:\LOGS\newsourcetype\link1` -> `D:\some\path\to\app\log_dir\ ` I'm having mixed results with this. Sometimes it reads all the logs in the original dir fine and continues to update. Other times it only reads what's there at startup. Once they roll, it stops updating until I restart Splunk again.

Viewing all articles
Browse latest Browse all 47296


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>