We have our Splunk instance on cloud and to monitor each source type we have created a folder on a shared drive.
Each CSV file of a particular source type is extracted from a database and then from that folder, we are getting the data into Splunk.
Earlier I created that folder on my system and it was working fine and even with one drive it is working fine but with share drive, it is unable to recognize the path.
We have provided that necessary path and index in input and output.conf.
Please help.
Please check "Supported file systems". I think that it is good to transfer by inserting UF.
http://docs.splunk.com/Documentation/Splunk/7.0.2/Installation/Systemrequirements
Does the splunk user have permission to read from the shared drive?
Yes we have permission
write a small python script and run this script using Splunk script stanza and check whether this script is able to get the contents from shared folder
Hello jangrid,
Actually i am a dot net programmer with no knowledge on python language.
Please provide a sample (python program) of the requirement
Thanks in advance
Hi @ASISH_9 you can use dot net program as well if your Splunk main instance installed on Windows machine.
can you provide your sample inputs.conf
Please find the working and not working stanzas of input.conf file as below and give your inputs
[monitor://C:\OneDrive - Accenture\Extracted Delta Files\TimesheetMaster\Timesheet*] ---[Working]
disabled = 0
index = slb_index
sourcetype=TimesheetMaster_03102016_2.csv
[monitor://Z:\TimeTracker_SharePoint\TimesheetMaster\Timesheet*] -------------[not working]
disabled = 0
index = slb_index
sourcetype=TimesheetMaster_03102016_2.csv
[monitor://\10.194.186.53\SLB-ADM_Applications$\TimeTracker_SharePoint\TimesheetMaster\Timesheet*] ---[not working as well]
disabled = 0
index = slb_index
sourcetype=TimesheetMaster_03102016_2.csv
Thanks in Advance